In recent days, IT security incidents have come to light at industry giants Microchip and Toyota. The IC manufacturer Microchip recorded a reduction in production, while Toyota lost large amounts of data.

Important findings

  • Microchip reports production outages due to a cyberattack.
  • Toyota initially denies the data loss, but later admits that data was stolen by a third party.
  • The full impact of the incidents is still unclear.

Toyota: data loss and confusion

The criminal organization ZeroSevenGroup claims to have broken into a Toyota plant in the USA and stolen around 240 GB of data. This data includes contacts, finances, customers, employees, photos, databases, network infrastructure, emails and many other sensitive information. The data should be freely downloadable via provided links, with the files having the date of 25 December 2022. It remains unclear when the break-in actually took place.

Toyota initially acknowledged to BleepingComputer: “We are aware of the situation. The issue is limited and is not a system-wide problem.” The company added that it was in contact with those affected and providing support where needed. However, Toyota did not say when the breach occurred, when it was discovered or how the attackers gained access. The number of people affected also remained unclear.

The following day, Toyota backtracked and told other media that Toyota Motor North America’s systems had not been compromised. The data had apparently been stolen from a third party that was incorrectly identified as Toyota. However, Toyota did not name the company affected.

Microchip: Production failures due to cyberattack

The IC manufacturer Microchip, which produces various electronic components for the automotive sector, has submitted a so-called K8 form. Listed companies must use this form to report IT incidents to the Securities and Exchange Commission (SEC).

The K8 form submitted on Tuesday of that week states that Microchip noticed potentially suspicious activity in its IT systems on Saturday, 17 August. After discovering this, the company took steps to contain and counter the potentially unauthorised activity. On Monday, 19 August, it discovered that unauthorised third parties had disrupted the use of certain servers and business operations. Microchip therefore took further measures to address the incident, including isolating the affected systems, shutting down some systems and launching an investigation with external cyber security experts.

As a result, some production facilities operated at lower capacity than usual. The ability of the company to fulfill orders has been affected. The company is working hard to bring the affected parts of the IT systems back online, resume normal business operations and limit the impact of the incident. The investigations are still ongoing. The full extent, origin and impact of the IT incident are still unknown. It is not yet possible to estimate whether the incident will affect the company’s finances or business results.

Microchip did not comment on whether ransom demands were made, i.e. whether it was a ransomware attack or who was behind the attack.

At the end of July, the German government announced that there had already been 42 cyberattacks against German economic institutions since 2022. This is currently one of the biggest threats to organizations and businesses. Such attacks occur daily.

Sources

IT security incidents at Microchip and Toyota, heise online.