Desk live·
ForensicPost
Cloud/Exposure/File 23-0512

Toyota Says Vehicle Location Data for 2.15 Million Customers Was Exposed for a Decade

A cloud database was configured so that anyone could read it without a password, and stayed that way from November 2013 to April 2023. The company attributed it to insufficiently explained data handling rules — which is to say nobody was ever told the setting mattered.

Constructed geometry · not a chart of case data
JurisdictionJapanthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetToyota Motor Corporation
ActorExposure
D. Kennedy11 min readConfidence: high2 sources reviewed

Toyota Motor Corporation disclosed that a misconfigured cloud environment had made data readable without authentication from 6 November 2013 to 17 April 2023, affecting around 2,150,000 customers — subscribers to its connected services.

The exposed data was reported to include vehicle location information and the times vehicles were at those locations, together with in-vehicle terminal identifiers and vehicle identification numbers. The company attributed the misconfiguration to insufficient explanation and thoroughness of data handling rules.

Nine And A Half Years

This is the longest exposure window in this database by a wide margin. It is not a dwell time — nobody was inside, because nobody needed to be.

The corpus records exposure as its own category, at 23-0918 for a Microsoft storage token and 26-0615 for an Elasticsearch instance. What distinguishes exposure from intrusion is that there is no event to detect: the system is behaving exactly as configured, continuously, for as long as nobody re-reads the configuration.

Location History Is Not A Field Among Fields

A decade of where a vehicle was and when is a decade of where a household was and when. It reveals home, workplace, school run, clinic, place of worship and every pattern in between, and unlike a card number it describes conduct rather than an account.

The corpus argues at 26-0110 and 26-0326 that consumption and presence records are treated as low-sensitivity by regimes written for financial fields, and this file is the strongest instance of that mismatch it holds.

Nobody Can Say Who Read It

The desk records no figure for how much of the data was actually retrieved, because none exists. An open database does not log the difference between a scanner and an interested party.

That is the honest position and it is also the unsatisfying one: the affected population cannot be told whether anything happened to them, only that it could have, for nine and a half years.

How we reported this

Built on contemporaneous reporting of Toyota’s disclosure. The 2,150,000 figure, the 6 November 2013 to 17 April 2023 window, the affected services and the company’s stated cause are Toyota’s own. Reporting during the same period described further Toyota cloud exposures affecting other populations; those are separate incidents and are not merged into this file or its figures. No claim is made about whether the data was retrieved — no such record exists. Graded high on the exposure, its window and its scope. Corrections: corrections@forensicpost.com.

Sources
  1. Toyota: Car location data of 2 million customers exposed for ten yearsBleepingComputer
  2. Cloud misconfiguration causes massive data breach at Toyota MotorCSO Online
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary