BleepingComputer reports that Toyota Motor Corporation subsidiary Toyota Financial Services has disclosed that its German customers had their data compromised following an intrusion against some of its European and African systems last month, which has been claimed by the Medusa ransomware gang.
Initial investigation revealed that attackers were able to exfiltrate customers' full names, contact details, residence addresses, lease purchase deals, and International Bank Account Numbers, although more data could have been stolen in the incident, said TFS in breach notification letters sent to affected clients.
No further details have been provided regarding the extent of the attack, including the number of affected individuals.
Such a development comes after Medusa ransomware decided to expose all of the data stolen from TFS on its leak site, indicating that Toyota may have refused to pay the demanded $8 million ransom within a 10-day deadline.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Aside from primarily leveraging basic usernames for their accounts, organizations impacted by ransomware intrusions from July to September — including those in the government and healthcare industries — also mostly failed to implement multi-factor authentication that could have deterred brute-force attacks.
Included in the Phobos-hit organizations that paid a ransom were a California public school system, a North Carolina children's hospital, a Maryland-based accounting and consulting service provider, and health organizations in Pennsylvania and Maryland, revealed an unsealed indictment against suspected Phobos administrator Evgenii Ptitsyn.
Alleged Scattered Spider hackers Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan have been indicted for their involvement in a prolonged cryptocurrency theft operation that involved SMS phishing, corporate system compromise, and further phishing intrusions.