On 26 February 2022 Kojima Industries, a supplier of plastic and electronic components to Toyota, discovered a malware infection and a threatening message after a server error forced a reboot. On 1 March Toyota suspended operations on 28 lines across all 14 of its plants in Japan.
Reporting places a single day of Toyota’s Japanese output at roughly 10,000 vehicles, around 5% of monthly domestic production. The shutdown lasted about a day; Kojima’s own systems took closer to a month to restore.
Just-In-Time Has No Buffer By Design
The reason a components supplier can stop an assembly line is that the system is built to have nothing spare. Inventory is waste; parts arrive when needed. That is not a flaw in the implementation, it is the implementation, and it is the reason Toyota’s method was studied and copied for forty years.
The corpus records the same property elsewhere — 24-1121, where a supply-chain platform decided what supermarkets could order, and 26-0704, where airports shared one IT platform. Efficiency and fragility are the same measurement read in two directions.
The Dependency Was Not Visible In The Contract
Kojima is small relative to Toyota. Nothing in the commercial relationship would identify it as capable of halting the manufacturer’s entire domestic operation, because the relevant property is not the supplier’s size but whether anything else can supply that part in time.
This is the assessment problem the corpus keeps recording: 26-0713, where a support vendor most customers had never heard of turned out to sit inside the trust boundary, and 22-0120, where an identity provider’s outsourced help desk did. Third-party risk scored by vendor size measures the wrong thing.
Availability, Counted For Once
No customer data is known to have been taken and no individual was notified. Under most disclosure regimes there would be nothing here to report at all.
The reason this incident has a number attached is that manufacturing output is measured publicly by other people for other reasons. The corpus argues at 24-1231 and 22-0224 that availability harm goes uncounted; Toyota is the case where an unrelated accounting system happened to be watching.
Built on contemporaneous reporting of the shutdown and its restart. The 26 February 2022 discovery at Kojima Industries, the description of malware and a threatening message following a server error, the suspension of 28 lines across 14 Japanese plants on 1 March, the roughly one-day duration, and the ~10,000 vehicles / ~5% of monthly domestic output figures are as reported. No ransomware operation is named: none was authoritatively attributed at the time and this desk does not assign one retrospectively. One search result offering a CVE identifier for this incident was disregarded as unreliable — no CVE was established as the entry route, and this file asserts none. Graded high on the operational facts, and the file records no entry route because none was established. Corrections: corrections@forensicpost.com.