A threat actor group named ZeroSevenGroup claims to have breached a branch of Toyota, one of the world's largest automotive manufacturers, in 2024. The group alleges that it gained access to an extensive range of sensitive data and shared the files online. ZeroSevenGroup stated they had persistent access to Toyota's U.S. branch before making the breach public.
The alleged breach involved 240 GB of data, which ZeroSevenGroup claims includes contacts, financial records, customer data, employee details, network infrastructure, email communications, and databases. They also claim to have obtained detailed Active Directory Recon (AD-Recon) data for the entire target network, including passwords. This information comes from reports only and has not been officially confirmed by Toyota or any regulatory body. The number of affected individuals and the specific states affected remain unclear.
Details about this incident are still emerging and may be subject to change as more information becomes available. Official notices may be delayed.