Toyota confirms customer and employee data stolen, says breach at third party to blame


Last week, a cybercriminal using the handle ZeroSevenGroup dumped 240GB of data on the infamous stolen data site BreachForums, that they said came from a hack on the US branch of car manufacturer Toyota. ZeroSevenGroup claims the dump includes customer and employee data.

Toyota told BleepingComputer that a breach at a third party had led to the data theft. After they looked at the files, BleepingComputer concluded that they had been stolen or at least created on December 25, 2022. The car vendor has already notified impacted individuals, but it did not provide technical details about the incident.

Read more…
Source: Malwarebytes labs


Sign up for our Newsletter


Related:

  • Uber concealed huge data breach

    November 21, 2017

    Uber concealed a hack that affected 57 million customers and drivers, the company has confirmed. The 2016 breach was hidden by the ride-sharing firm which paid hackers $100,000 (£75,000) to delete the data. The company’s former chief executive Travis Kalanick knew about the breach over a year ago, according to Bloomberg, which first broke the news. The hackers ...

  • Your biggest threat is inside your organisation and probably didn’t mean it

    November 19, 2017

    It doesn’t have a super-sexy moniker like KRACK or Heartbleed, but the spectre of the insider threat looms large for organisations, and has done so for as long as electricity, silicon, and computing have been paired up to store information. While it’s easy to imagine a disgruntled, unhappy employee becoming a malicious actor within an organisation, and dumping the ...

  • Equifax spends $87.5 million on data breach, more expenses on deck

    November 9, 2017

    Equifax spent $87.5 million in the third quarter on its recent data breach. The disclosure came amid an earnings report that showed revenue growth of 4 percent to $834.8 million and net income of $96.3 million. In other words, the data breach affecting 145 million Equifax customers dented the cash cow, but it certainly didn’t kill it. Read more… Source: ZDNet  

  • Millions of Malaysian phone users’ data stolen: Report

    November 1, 2017

    The personal details of some 46.2 million mobile phone subscribers in Malaysia have been stolen, in what is believed to be the largest data breach in the country, local media reported yesterday. Online technology site lowyat.net said the hackers have the home addresses, identity card numbers, SIM card information and private details of almost the entire ...

  • Bermuda cyber hack: Offshore law firm data hack leaves super-rich bracing for financial details to be released

    October 25, 2017

    A leading offshore law firm with clients including the super-rich and international corporations has revealed it suffered a “data security incident” that may result in customers’ private information being leaked. Bermuda-based Appleby, which has offices in a number of British overseas territories, said some of its data had been “compromised” in the 2016 cyber incident. The firm ...

  • Data breach hits 30m South Africans

    October 18, 2017

    The personal information of about 30 million South Africans has been compromised. This was revealed by Australian-based IT security researcher Troy Hunt. He created the Have I been pwned? platform as a free resource for anyone to quickly assess if they may have been put at risk due to an online account of theirs having been compromised or “pwned” in a data breach. Following the ...