Toyota Motor Corp disclosed that the vehicle data of around 2.15 million users was publicly accessible in Japan for nearly a decade, from November 2013 to mid-April 2023.
The data breach was caused by a database misconfiguration that was accessible to anyone without authentication.
According to Toyota spokesperson Hideaki Homma, the issue with Toyota’s cloud-based Connected service affects only vehicles in Japan. The service provides vehicle owners with maintenance reminders, entertainment streaming and emergency assistance.
The compromised data includes vehicle identification numbers, location history and video footage captured by the vehicle’s drive recorder. However, so far there is no reports of any issues due to the breach.
Toyota claims this information cannot be used to identify individual owners. Still, approximately 2.15 million users of services like G-Link, G-Book and Connected have been affected. The company confirmed it has now fixed the system issue and assures customers that their Connect-enabled vehicles are safe to drive without the need of any repairs.
A Toyota spokesperson commented that there was a lack of active detection mechanisms to identify the mistake, so the data was exposed for almost a decade.
The announcement comes months after Toyota warned that nearly 300,000 customers may have had their personal data leaked after an access key was publicly available on GitHub for almost five years.















Comments