Toyota T-Connect source exposure
Source summary
Toyota reported that T-Connect source code had been publicly accessible on GitHub and contained a data-server access key. Toyota said 296,019 email addresses and customer management numbers may have been accessible.
Toyota noticeTechnical context
A contractor uploaded source with an access key under a public repository setting. Toyota reported making the source private and changing the key after discovery.
Engineering guidance
Keep credentials out of source, scan before publishing, monitor repository visibility, and revoke exposed keys rather than only deleting the file.