Toyota Financial Services (TFS) is warning customers about a data breach, which includes the exposure of personal and financial data.

Toyota Financial Services is a subsidiary of Toyota Motor Corporation and is a global entity with a presence in 90% of the markets where Toyota sells its cars.
In November, the company discovered unauthorized access to some of its systems in Europe and Africa. The Medusa had previously publicly said it had gained access to the Japanese automaker's systems.
The attackers demanded $8,000,000 from the company to delete the stolen data and gave Toyota 10 days to respond.
See also: Austal USA: Data breach by Hunters International?
After detecting the unauthorized access, the company took some systems offline to contain the breach, which also affected customer services.
Apparently, Toyota did not agree to pay the ransom demanded by the ransomware group, so the cybercriminals leaked the data to the site on the dark web.
Earlier this month, Toyota Kreditbank GmbH in Germany was identified as one of the affected divisions and admitted that hackers gained access to personal customer data.
German news agency Heise obtained a sample of the notifications Toyota sent to German customers, informing them that the following data had been breached:
- Full name
- Residential address
- Contract information
- Lease-purchase details
- IBAN (International Bank Account Number)
Toyota customers should be very careful going forward, as this information could be used by cybercriminals for phishing, social engineering, financial fraud, and more.
See also: Norton Healthcare: May ransomware attack led to data breach
The customer notification confirms that the above data was leaked onto the dark web. However, the internal investigation is not yet complete, which means that the attackers may have accessed other information as well.
Toyota promises to immediately notify affected customers.

Consequences of a data breach
A company that has suffered a data breach faces multiple consequences. First, customer trust can be severely undermined. Customers will be concerned about the security of their personal and financial information and may decide not to continue using the services . This can lead to a loss of customers and a decrease in revenue for the company.
Additionally, the company may face legal consequences. Depending on applicable law, the company may be subject to fines or face lawsuits from customers affected by the breach of their personal data. This could have serious financial consequences for the company, including the compensation it must pay to customers who have suffered losses.
See also: Tipalti: Investigates allegations of BlackCat ransomware gang breach
To address these consequences, the company must take immediate steps to restore customer trust. This may include notifying customers about the breach, offering free credit protection or other security measures, and reaffirming its commitment to protecting customers’ personal data. In addition, the company must strengthen its security measures to prevent future data breaches.
Source: www.bleepingcomputer.com
