Data of 296,000 Toyota customers leaked via website source code on GitHub
Data from 296,000 Toyota customers has been leaked. This is because some of the source code from the Toyota Connect website has been available through a public GitHub account for five years. The source code contained a key that provided access to the customer data server.
Toyota Connect is an app that allows Toyota owners to see information about their vehicle. Users can create an account through the official website of the app. The car manufacturer explains that the company’s relevant GitHub account has created the Toyota Connect website. However, this account turned out to be public. This made the source code accessible to everyone from December 2017 to 15 September 2022, the day Toyota discovered the leak. On the same date, the GitHub account was made private. Two days later, the key in the source code has been changed.
The leaked data consists of the email addresses and customer numbers of 296,019 customers. Other details, such as names, phone numbers and payment details, have not been leaked, Toyota said.
The manufacturer says it has had research carried out by security experts. It has not yet become clear whether third parties have had access to the server. However, Toyota cannot rule out the possibility that the leak may have been exploited and so it has notified affected customers.