Toyota Confirms Ransomware Attack, Data Breach

%20(1).png)
Introduction
Toyota Finance Services (TFS), a subsidiary of the well-known automaker, has confirmed that they were hit with a ransomware attack. TFS detected unauthorized access to some of its systems in Africa and Europe after cybercriminals claimed an attack on the company. The cybercriminals, also known as the Medusa ransomware gang, claims responsibility for the attack.
Summary of the incident
The Medusa ransomware gang had listed ‘Toyota Financial Services’ to its data leak site on the dark web and demanded a ransom payment of $8,000,000 to delete allegedly stolen data. The cybercriminals published sample data that included financial documents, hashed account passwords, passport scans, etc. to prove the intrusion. As of right now, the incident is limited to Toyota Financial Services Africa & Europe. A spokesperson announced that the process of bringing their systems back online is already underway.
How to stay safe
- Reset All Passwords – If you are reusing passwords across different websites, reset those passwords and employ hard-to-guess, complex passwords on those websites.
- Password Manager – To keep track of your complicated passwords, think about investing in a password manager. Password managers, like 1Password, place a secret key on your password manager to add a unique extra layer of security.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
Subscribe to receive our latest news and insights in your inbox each week.
Protect your digital life by detecting risks before they escalate
Richter Guardian gives you enterprise-level cybersecurity tailored for individuals, families, and executives.

Related posts

Introduction
In May 2023, the Cl0p ransomware group started exploiting a newly discovered vulnerability in Progress Software’s MOVEit Transfer, a tool for enterprise file transfer. Although Progress swiftly released a fix, the impact was already significant. This extensive cyberattack by Cl0p targeted a wide range of sectors globally, affecting entities such as the public school system in New York City, a UK-based company providing HR and payroll services to clients like British Airways and the BBC, among others.
Over 2,000 organizations have reported being attacked, with data thefts affecting more than 62 million people
Fallout of the incident
With such a large exposure, many people have begun to receive notices that their personal information was compromised as part of this breach. Many of the organizations that people entrust their data to, like accounting firms and wealth management companies, were affected by this breach. Companies affected by this breach have a legal obligation in Canada to report to their customers if they believe their customers have had their personal information breached.
Companies that notify their customers of the breach often offer one to two years of credit monitoring and identity protection services at no cost.
Richter recommends that victims receiving these notices enroll in the free credit monitoring and identity protection services provided.
Implications
The diagram on the right illustrates how hackers use personal information to carry out attacks using your personal information. Credit monitoring and identity protection services can assist with identity theft and financial fraud implications; however, this protection is insufficient.
Hackers can still use your personal information to conduct blackmail and ransom operations. They can impersonate you online and wreak havoc on your social reputation. They can use it to mount very sophisticated phishing attacks.
Recommendations
Richter Guardian is a state-of-the-art service that gives you exclusive access to commercial-grade protection unavailable in the consumer market.
By protecting your online presence, Richter Guardian will defend you from impersonations, inadvertent leakage of critical data and worse, any compromise to your digital safety. By protecting your devices, Richter Guardian will thwart sophisticated phishing and other technical attacks. You can rest assured that our seasoned cybersecurity professionals are there for you to address any of your cybersecurity concerns.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.

What the IDScan.net breach means for high-net-worth individuals, executives and their family members who have a Canadian driver's licence
On September 1, 2026, cybersecurity journalist Brian Krebs found a listing on the dark web called Nexus selling scans of more than 153 million driver's licences from Canada and the U.S.A. The images appeared to come from an identity verification company most people have never heard of: IDScan.net.
Have you ever handed your driver's licence to a retail store cashier, nightclub manager, hotel front desk clerk or car rental agent? If yes, this breach may impact you.
If matters even more if you run a company, sit on an advisory board or manage family wealth.
Here is what we know, why it hits harder at the high-net-worth level, and what a smart response looks like.
What we know so far
The information that follows comes from Krebs on Security, Global News, Yahoo Finance Canada and IDScan.net itself.
These identity files claimed 153 million driver's licences, 10 million ID cards, 3 million travel documents and 579,000 medical cards. About 1.1 million records were Canadian, and Ontario had the most, at 473,673.
Krebs said a record could include front and back images, plus infrared and ultraviolet scans. He checked nine people's records. Each had travelled on or near the date stamp, including at a car rental counter and a cannabis dispensary.
IDScan.net sells ID scanning software to businesses such as bars, casinos, car rental firms and cannabis shops. The company's September 4th notice said an unauthorized party may have accessed or copied customer data, including names and ID numbers. IDScan.net said full access required payment, and it offered free credit monitoring.
Officials then stepped in:
- The FBI said on September 2 that it was looking into the incident. The RCMP also said it was monitoring the situation.
- On September 21, Privacy Commissioner Philippe Dufresne opened a formal investigation. The investigation will examine IDScan.net's security safeguards and whether it properly told affected people, under PIPEDA, Canada's federal private-sector privacy law. CBC and The Spec also covered the announcement.
One caution: the big numbers come from the seller and from Krebs. Global News reported that neither the RCMP nor the Canadian Centre for Cyber Security has confirmed them.
IDScan.net has not said how many Canadians are affected. Krebs reported that Nexus went offline soon after his story ran. A site going dark does not mean copied data disappears.
Why your Canadian driver's licence is more than just an identity card
A driver's licence holds your full name, home address, birth date and ID number, plus your photo. Yahoo Finance reports that modern scanners capture both sides of the card and often send the image to cloud servers.
Criminals can use those details to open credit in your name. They can also write scams that sound real, because they know things about you.
Experts told Global News that phishing emails and texts are the likely next step. They also said that once data is out, there is little you can do to pull it back. And you can't reset your face like a password.
Researchers have warned that AI photo-matching tools make stolen photo scans a real concern.
Why this breach in particular matters for high-net-worth individuals, executives and their family members
You have increased visibility
Security researcher Zach Edwards said, "There's never been a breach of driver's licences at this scale." He added that the ongoing nature of the breach created national security risks for high-profile people.
Krebs found licences of senior U.S. officials for sale. Cybernews reported that analysts see celebrities, politicians, lawyers and wealthy people as especially exposed.
For a prominent family, a name, address and face are a strong starting kit for a targeted scam, or something worse. A driver's licence scan is also easy to pair with public facts about you, like your company, your donations and your advisory board seats.
You have heightened responsibility
If you lead a business, a family office or an estate, your identity is a key that opens other people's money. A criminal posing as you can call a bank, email an advisor or pressure an assistant. The damage can be financial, and it can hurt your reputation too.
You deal with added complexity
Wealth means more properties, vehicles, trips, accounts and people acting on your behalf. Your adult children get scanned at clubs. An assistant rents a car. A house manager registers a guest. Each one is another vendor holding another copy.
There is a bright side: Wealth buys excellent lawyers, accountants and security advisors. The problem is that each sees only their own slice. No one often sees the whole picture.
You can't audit every vendor
The privacy commissioner's investigation matters. Under PIPEDA, businesses must protect the data they collect. Unfortunately investigations come after the breach, and your driver's licence was sitting with a company you never chose, after a scan you didn't think twice about.
A modern approach: Assume you are exposed, but limit the damage
Good security today does not depend on keeping every secret. It assumes some of your data is already out there, then makes it hard to use. Five habits help:
1. Ask for a visual check
Yahoo Finance notes you can usually ask staff to look at your card instead of scanning it. You can also ask where scans are stored.
2. Watch your credit
Pull your reports from TransUnion or Equifax, and consider a fraud alert. The RCMP also urges people to monitor financial and government accounts and to report fraud to police and the Canadian Anti-Fraud Centre.
TransUnion is included with your Richter Guardian subscription.
3. Lock down your accounts, including email addresses and social media
Use strong, unique passwords and multi-factor-authentication (MFA) everywhere, as the Canadian Centre for Cyber Security advises. Start with your email addresses and social media accounts, for everyone in your family.
4. Set a family "verify first" rule
Any urgent request for money, access or documents has to be confirmed through a second channel, like a call to a known number. This should cover assistants, advisors and adult children.
5. Get a single, comprehensive and ongoing view of your digital risk level
Someone should watch the whole household, not each account on its own.
You can start making these first four changes today.
The fifth is difficult and time-consuming to do alone, and where Richter Guardian delivers as a modern personal cybersecurity program for high-net-worth individuals, executives and their families.
Where Richter Guardian fits
Richter Guardian can't pull a licence out of a dark web vendor's database. No one can. What we can do is watch the doors criminals try next.
After a government ID leaks, attackers still need to act like you. That often means taking over an email account or social account, or building a fake profile.
Richter Guardian's reputation and identity protection is built for that moment. It works in four steps:
Understand
We begin by understanding your personal digital environment, including the devices and accounts you rely on, your social media presence, and where exposure is most likely to exist.
Monitor
24 hours a day, 7 days a week, our monitoring and prevention runs quietly in the background. Richter Guardian helps identify meaningful risk signals tied to your personal digital life.
Surface
When something matters, our team of cybersecurity experts will review it. We share with you the context and priority, so you know why it's important. This can be done via the Richter Guardian mobile app, telephone, email, online video or in-person.
Guide
If action is needed, Richter Guardian's human-led team, known as the Cyber Defence Desk help you decide next steps, discreetly.
Instead of a flood of alerts, you get what matters: Summary and guidance explained in plain language, and a human to talk to and lead you through the situation.
Our team can also coordinate with your existing advisors or IT service provider, so your family office, lawyer and bank aren't left guessing. Richter Guardian fits into a busy life instead of interrupting it.
Take the next step: Request a private consultation or complete a brief assessment
A breach like this is a good opportunity to look at you and your family's digital risk level, before someone else does.
Request a private consultation. Discuss the identities and accounts you want protected, and ask us any questions. It's confidential and no-obligation.
Not yet ready to talk? Try our What's my risk? assessment. It takes a few minutes, needs no sensitive details, and your summary arrives by email.

PetSmart Warns Customers of Credential Stuffing Attack
Introduction
PetSmart, a pet retail giant in the United States, is alerting certain customers about password resets resulting from an ongoing credential stuffing attack attempting to breach existing accounts. The company released a statement on March 6 to let customers know about the credential stuffing attack.
As a precaution, PetSmart reset the passwords for any accounts logged in during the credential stuffing attack. Additionally, they reassured customers that there was no evidence of compromise to petsmart.com or any of their systems during the incident.
What is credential stuffing?
A credential stuffing attack is a type of cyber-attack in which threat actors use previously acquired usernames and passwords, typically obtained from data breaches, to gain unauthorized access to user accounts on various online platforms.
Threat actors usually automate the process of trying these login credentials across multiple websites and services. Threat actors are cognizant of the fact that people commonly reuse passwords across various accounts, making them even more inclined to exploit this widespread behavior.
How to protect yourself against credential stuffing attacks
Although cyber breaches may be unavoidable, you can still prevent breached details from being used on other websites or services by taking the following precautions:
- Use Unique Passwords For Each Account – Minimize the impact if one account is compromised.
- Enable Multi-Factor Authentication (MFA) – Implement MFA wherever possible to add an additional layer of security.
- Update Outdated Passwords – Change your passwords periodically, especially for critical accounts like email, banking, and social media.
- Limit Access – Only use trusted devices and networks to access sensitive accounts. Avoid logging in from public computers or unsecured Wi-Fi networks to access sensitive accounts. Ensure that you are not saving your credentials on a public computer.
Ready to stay protected from digital threats, with experienced professionals overseeing your security?
Request a private consultation to find out whether Richter Guardian is a good fit for you.
.png)
