Toyota confirms third-party data breach impacting customers
bleepingcomputer.com
bleepingcomputer.com
> They also claim to have collected network infrastructure information, including credentials, using the open-source ADRecon tool that helps extract vast amounts of information from Active Directory environments.
> One day later, a spokesperson clarified in a new statement shared with BleepingComputer that Toyota Motor North America's systems were "not breached or compromised," and the data was stolen from what appears to be "a third-party entity that is misrepresented as Toyota."
I wonder if the third party entity is Microsoft and it was their Azure AD, exchange, sharepoint, onedrive, etc that was accessed. If so it's an interesting word choice to use to try to dodge responsibility and criticism.
It's also highly likely that Toyota Motors NA contracted out IT work to said third-party, as is the norm at most non-Software companies because IT is a cost center (just like how Payroll and Accounting tends to be contracted out at Software companies).
Snowflake got hit by a similar incident when Polish (edit: Ukrainian) EPAM contractors' laptops were compromised [0], leading to a massive breach org-wide and for dozens of F1000s
[0] - https://techcrunch.com/2024/06/05/snowflake-customer-passwor...
https://www.bleepingcomputer.com/news/security/cdk-global-cy...
If you give your data to a third party, you are still fully responsible for the security of that data. Don't trust the third party? Don't give them the data.
It sucks, because I don't necessarily know how you could codify the difference here. If you said that Amazon was sharing customer emails and purchases with a third party, that is indeed suspicious as heck. When you restate that they email you receipts with this information, it sounds a lot different. Indeed, it was very inconvenient when they didn't do that.
This is also why most hospitals have that ridiculous, "you have a new message on the portal" emails. Which are so infuriating.
I don’t expect Toyota to be very good at IT. But I expect them to somehow figure out if they are working with incompetent or evil third parties, because they also buy airbags and brakes from third parties, so like, they should be good at evaluating their vendors.
You put something in a storage locker with a key. Someone nefarious asks you for the key, and steals your things out of the storage locker. Then you blame the storage locker for unlocking to your key.
If you make this a financial liability, they (any company) are going to purchase insurance like anything else and then offset that cost to the customer - so you’ll just end up paying for it anyway.
Chubbs, AXA, and others are major players in the Cyber Insurance industry in 2024.
We were going the right path with recent SEC regulations, but those are up in the air now with the Chevron deference decision.
To companies taking out insurance, this can look like being denied coverage unless you have evidence of good practices.
But criminal statutes for gross negligence would probably also help.
Otherwise, it's impossible to function as a society.
my identity has been in the wild for a few years and someone even used my identity to do credit card, buy phones and get new driver licenses, even claim IRS tax refund.
nowadays I check my accounts daily, that's the only thing I can do, to monitor things closely, I mean, on a daily basis, what else can I do.
don't mention the credit alert etc, the impostor set that up before me, they had everything about me, and yes I got letters that my info was leaked multiple times over the years.
https://my.equifax.com/membercenter/#/freeze
https://usa.experian.com/mfe/regulatory/security-freeze
https://service.transunion.com/dss/freezeStatus.page
NOTE: do not pay for this service from any of these companies. Placing and lifting a credit freeze is a free and nearly instantaneous action.
NOTE 2: you may need to try the link multiple times as the login action sometimes takes you away from the requested page (Experian…)
I’ve been part of so many data breaches by now - some of them from companies I’ve never interacted with, just because another company shared my data with them. That was the moment I realized that I just can’t trust corporations with my safety and went on the defensive.
Which reminds me, I still need to find a way to set up a new phone number for each company that requests it.