Toyota flags possible customer data leak in some countries

31 May 2023 - 07:46 By Reuters
subscribe Just R20 for the first month. Support independent journalism by subscribing to our digital news package.
Subscribe now
Toyota said on Wednesday information of customers in some countries in Asia and Oceania may have been left publicly accessible from October 2016 to May 2023 due to a setting error in the cloud environment. Stock photo.
Toyota said on Wednesday information of customers in some countries in Asia and Oceania may have been left publicly accessible from October 2016 to May 2023 due to a setting error in the cloud environment. Stock photo.
Image: vershininphoto/123rf

Toyota said on Wednesday information on customers in some countries in Oceania and Asia, excluding Japan, may have been left publicly accessible from October 2016 to May 2023.

Customer information that may have been accessible externally included names, addresses, phone numbers, e-mail addresses and vehicle identification and registration numbers, the company said.

The incident follows its announcement this month that the vehicle data of 2.15-million users in Japan, or almost the entire customer base who signed up for its main cloud service platforms since 2012, had been publicly available for a decade because of human error.

The world's largest carmaker by sales said the latest issue was discovered when it launched a broad investigation into cloud environments managed by Toyota Connected after the earlier incident.

“As we believe this incident was caused by insufficient dissemination and enforcement of data handling rules ... we have implemented a system to monitor cloud configurations,” Toyota said.

The issue arose because of a setting error in the cloud environment where the carmaker stored customer data collected by overseas dealers for handling and managing maintenance inspections of vehicles.

Toyota is investigating the issue based on the laws and regulations of each country, a company spokesperson said.

Toyota did not say how many customers were affected by the incident, in which countries and whether customers of its luxury Lexus brand were affected.

Through Connected, which is majority owned by the carmaker, Toyota offers individual and business customers mobility solutions, such as a smart key function, a 24-hour operator and location-based route guidance and traffic congestion information services.

Only part of the customers' information may have been externally accessible, the company said.

Toyota had also investigated whether there were third-party copies or use of its customer data and found no evidence of such use, adding vehicle location and credit card information were not included in the incident.

It said customer information “may have been potentially accessible externally” but did not elaborate on how the information could have been accessed.

The company uncovered the incident announced this month by chance, during inspections that started on April 7, the spokesperson said.


subscribe Just R20 for the first month. Support independent journalism by subscribing to our digital news package.
Subscribe now

Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.

Speech Bubbles

Please read our Comment Policy before commenting.