The Daily Telegraph

Carmakers’ trade secrets exposed by data breach

- By Natasha Bernal

TEN years’ worth of data belonging to some of the world’s biggest carmakers including Toyota, Volkswagen, Fiat and Chrysler has been accidental­ly made available online, it has emerged.

Sensitive documents from over a hundred manufactur­ing companies – including confidenti­al trade secrets – were exposed on a server owned by Level One Robotics, a specialist engineerin­g company, according to Upguard, an Australian cybersecur­ity group that spotted the breach. Among the companies with data exposed are clients of Level One including divisions of VW, Chrysler, Toyota, General Motors, Tesla and Thyssenkru­pp.

According to Upguard, the 157 gigabytes of data available online include over a decade of assembly line schematics, factory floor plans and layouts, robotic configurat­ions and documentat­ion, ID badge request forms for employees, contracts and non-disclosure agreements.

The data was all available through rsync, software that allows companies to back up large data sets. The team first discovered the data breach earlier this month, prompting Level One, a Canadian company that supplies many of the world’s top car manufactur­ers, to shut down access.

Chris Vickery, the researcher who found the data, told The New York Times: “That was a big red flag. If you see NDAS, you know right away that you’ve found something that’s not supposed to be publicly available.”

Naaman Hard, a security engineer at Digital Guardian, a data loss prevention software company, said: “Companies must learn from incidents like this and apply the right methods of protection to their IT environmen­t, with the ability to apply security at the data-level being the most critical.”

According to Upguard, the permission settings on the rsync server indicates that the server was “writable”, meaning that someone could not just access informatio­n but alter it.

Milan Gasko, chief executive of Level One Robotics, said his company was made aware of a claim from Upguard about an incident involving access to a single backup drive, which contained various data. “As soon as we were informed, we took the backup drive offline, which immediatel­y eliminated the access. We have hired forensic experts to guide an investigat­ion into Upguard’s claims, identify what data may have been accessible … and to strengthen our systems,” he said.

“We regret any concern this has caused customers and staff, and believe we have taken all appropriat­e actions to rectify the situation.”

Newspapers in English

Newspapers from United Kingdom