5 ms·
> and were able to steal 240GB of files with information on Toyota employees and customers, as well as contracts and financial information, > They also claim t
by batch12 2y ago
> and were able to steal 240GB of files with information on Toyota employees and customers, as well as contracts and financial information,
> They also claim to have collected network infrastructure information, including credentials, using the open-source ADRecon tool that helps extract vast amounts of information from Active Directory environments.
> One day later, a spokesperson clarified in a new statement shared with BleepingComputer that Toyota Motor North America's systems were "not breached or compromised," and the data was stolen from what appears to be "a third-party entity that is misrepresented as Toyota."
I wonder if the third party entity is Microsoft and it was their Azure AD, exchange, sharepoint, onedrive, etc that was accessed. If so it's an interesting word choice to use to try to dodge responsibility and criticism.
- alephnerd 2y agoSounds more like a third party MSP for Toyota Motors NA based on the basic AD misconfigurations. It's also highly likely that Toyota Motors NA contracted out IT work to said third-party, as is the norm at most non-Software companies because IT is a cost center (just like how Payroll and Accounting tends to be contracted out at Software companies). Snowflake got hit by a similar incident when Polish (edit: Ukrainian) EPAM contractors' laptops were compromised [0], leading to a massive breach org-wide and for dozens of F1000s [0] - https://techcrunch.com/2024/06/05/snowflake-customer-passwords-found-online-infostealing-malware/?guccounter=1 https://techcrunch.com/2024/06/05/snowflake-customer-passwor...
- dapearce 2y agoReads a bit like it could have been a dealership or dealer network that was breached.
- bell-cot 2y agoYeah. Maybe this one, or closely related? https://www.bleepingcomputer.com/news/security/cdk-global-cyberattack-impacts-thousands-of-us-car-dealerships/ https://www.bleepingcomputer.com/news/security/cdk-global-cy...
- Workaccount2 2y agoI don't know why companies think that if a third party is breached and steals their data from them, said company somehow is any less culpable. If you give your data to a third party, you are still fully responsible for the security of that data. Don't trust the third party? Don't give them the data.
- taeric 2y agoI mostly agree for data given. With carve outs for data that is necessary for something. For a silly example, recall back when Amazon was hiding information in their emails so that they wouldn't be sharing purchase information with third parties. It sucks, because I don't necessarily know how you could codify the difference here. If you said that Amazon was sharing customer emails and purchases with a third party, that is indeed suspicious as heck. When you restate that they email you receipts with this information, it sounds a lot different. Indeed, it was very inconvenient when they didn't do that. This is also why most hospitals have that ridiculous, "you have a new message on the portal" emails. Which are so infuriating.
- bee_rider 2y agoIf anything it looks worse somehow… it takes it out of the “maybe they made a technical screw up, after all IT isn’t really a core competency for Toyota” into the “are they good at evaluating the parties they do business with?” I don’t expect Toyota to be very good at IT. But I expect them to somehow figure out if they are working with incompetent or evil third parties, because they also buy airbags and brakes from third parties, so like, they should be good at evaluating their vendors.
- basch 2y agoImagine in the physical world. You put something in a storage locker with a key. Someone nefarious asks you for the key, and steals your things out of the storage locker. Then you blame the storage locker for unlocking to your key.