Data Breaches

Toyota Italy accidentally leaked sensitive data

0

Toyota Italy accidentally leaked sensitive data and exposed secrets for its Salesforce Marketing Cloud and Mapbox APIs for more than one-and-a-half years, until this March.

The threat actors could abuse this information to gain access to Toyota clients’ phone numbers and email addresses and abuse them to launch phishing attacks.

On February 14, the Cybernews research team discovered an environment file (.env) hosted on the official Toyota Italy website.

According to the Cybernews research team, the company exposed credentials to the Salesforce Marketing Cloud, a provider of digital marketing automation and analytics software and services.

The threat actors could access these credentials to send bogus SMS messages and emails, edit and launch marketing campaigns, create automation scripts, edit content tied with the Salesforce Marketing Cloud, and even send push notifications to Toyota’s customers.

Toyota Italy also exposed software company Mapbox’s application programming interface (API) tokens, used to query map data. Even though the data is not as sensitive as the Salesforce Marketing Cloud credentials can be abused to query a lot of requests and rack up the cost for API usage for Toyota.

When Cybernews informed the company about the vulnerability, it took all the necessary actions to remedy the situation. According to Toyota, it was caused by a failure to follow the company’s data-security policies.

They have taken additional set of countermeasures to restore and strengthen the cybersecurity systems and protocols.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

 France bans all Fun apps from government devices

Previous article

Kimsuky hackers use new recon tool in cyberattacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *