← Incident database

toyota-github-2022 · Disclosed 2022-10-07

Toyota: access key in a public repository

Public T-Connect source code contained a data-server access key. Toyota disclosed potential exposure; third-party access was not confirmed.

CredentialsConfiguration / exposure

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    Code containing an access key was public from December 2017 to September 15, 2022.

    [s1]経緯と対応
  • Reported fact

    Potential exposure covered about 296,000 records; Toyota could neither confirm nor fully rule out third-party access.

    [s1]本文

Timeline

  1. Exposure identified and repository made private. [s1]

  2. Access key changed. [s1]

  3. Potential exposure disclosed. [s1]

Reported response

  • Reported fact

    The source was made private and the access key changed.

    [s1]経緯と対応

Evidence relevant to prevention

Operational controls to inspect

Inspect repository visibility and secret inclusion separately. Closing exposure does not revoke credentials already obtained.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

Unauthorized access or actual data theft is not confirmed in the cited disclosure.

Sources

  1. [s1] トヨタ自動車 · Primary source

    お客様のメールアドレス等の漏洩可能性に関するお詫びとお知らせ ↗

    Published 2022-10-07 · Reviewed 2026-10-02