Select Page

Incident: Toyota does U-turn, confirms thousands of Australian customers hit by latest data breach | drive.com.au

Incident: Toyota does U-turn, confirms thousands of Australian customers hit by latest data breach | drive.com.au

Australian Automotive Incident, 01 June 2023

Toyota does U-turn, confirms thousands of Australian customers hit by latest data breach

Access key was publicly available on GitHub for almost five years

Source: Toyota does U-turn, confirms thousands of Australian customers hit by latest data breach | drive.com.au
Source: Toyota discloses data leak after access key exposed on GitHub | beepingcomputer

News agency Reuters reports, in the latest computer hack, the vehicle data of 2.15 million Toyota customers in Japan – almost all owners who signed up for the company’s cloud services from 2012 – had been “publicly available for a decade due to human error”.

After initially saying Toyota customers in Australia were not affected, the company has since done a U-turn. However, Toyota Australia issued the following statement: “On 12 May 2023, Toyota Motor Corporation confirmed the vehicle data of some users in Japan had been publicly accessible due to an error in the configuration of a cloud-based database.

Toyota discovered recently that a portion of the T-Connect site source code was mistakenly published on GitHub and contained an access key to the data server that stored customer email addresses and management numbers.

This made it possible for an unauthorized third party to access the details of 296,019 customers between December 2017 and September 15, 2022, when access to the GitHub repository was restricted.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

OpenAI apologizes to Australia after its AI agents breached government sites

OpenAI on Monday apologized to the Australian government for not immediately notifying the country’s administration that its agents had breached some public services websites. The company also detailed how some [...]

Australia’s legacy systems were already a cyber risk. AI agents are raising the stakes

In the days since an artificial intelligence (AI) agent operated by OpenAI gained unauthorised access to a Services Australia portal holding Medicare … [...]

The US could send Australian personal data to third countries under secret ‘partnership’

While the Albanese government stays silent on plans to hand citizens' biometric data to the Trump administration, the Europeans have publicly … [...]

Cyber Threat Landscape - Australia and New Zealand - CYFIRMA

Published On : 2026-09-25 EXECUTIVE SUMMARY A regional pattern with sector-specific expression Identity and access, not novel exploitation, is the … [...]

OAIC’s action in relation to the 2023 Latitude Data Breach and information to update and assist individuals

On 10 May 2023, the OAIC commenced an investigation into the personal information handling practices of the Latitude group of companies[1] (Latitude). … [...]

China seizes sensitive F-35 parts diverted from Australia

Washington | The Chinese government has taken possession of potentially sensitive F-35 stealth aircraft parts that were inexplicably diverted to Hong … [...]

NAB restores systems following online outage impacting customers

Major Australian bank NAB has restored systems following online outages that prevented customers from using their services. • Thu, 24 Sep 2026 • … [...]

OpenAI breach strengthens Australia's case for tougher AI safety rules

An unprecedented breach of a government website by a rogue OpenAI agent will sharpen Australia's push to impose stricter safety, transparency and … [...]

Quest tells customers to replace passports after security breach | ABC NEWS

The hotel company, Quest, is warning customers they may need to replace their driver's licences and passports. It comes after a cyber hack last month exposed swathes of personal information, [...]

Why did it take OpenAI three months to report the Medicare hack? | ABC NEWS

The federal government has raised concerns about uncontrolled and unauthorised AI activity after an AI model infiltrated a Medicare platform owned by Services Australia. The OpenAI agent accessed data not [...]

OpenAI agent hacked into Medicare to access data, prime minister says | ABC NEWS

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare portal earlier this year. The OpenAI agent reportedly gained unauthorised access to private and public data [...]

Health data attack the 'first' government hack by autonomous AI, researchers say

A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading