{"id":2291,"date":"2022-03-03T03:58:04","date_gmt":"2022-03-03T10:58:04","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2291"},"modified":"2022-03-04T13:52:18","modified_gmt":"2022-03-04T20:52:18","slug":"ransomware-attack-on-toyota-motors-halts-production-across-japan","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/03\/ransomware-attack-on-toyota-motors-halts-production-across-japan\/","title":{"rendered":"Ransomware attack on Toyota Motors, halts production across Japan"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Toyota Motor Company suspended all factories in Japan on Tuesday, March 1,&nbsp;&nbsp;after a critical supplier suffered ransomware that disrupted the automaker&#8217;s parts supply management system. The Japanese automobile giant had to suspend 28 production lines at 14 factories across Japan for 24 hours.<sup>1<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a statement on March 1, 2022, Toyota said: \u201cWe would like to apologize again to our customers, suppliers, and other related parties for any inconvenience caused by today&#8217;s sudden shutdown.\u201d<sup>2<\/sup><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.17.46-AM-1024x558.png\" alt=\"\" class=\"wp-image-2294 lazyload\" width=\"701\" height=\"382\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.17.46-AM-1024x558.png 1024w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.17.46-AM-300x164.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.17.46-AM-768x419.png 768w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.17.46-AM.png 1293w\" data-sizes=\"(max-width: 701px) 100vw, 701px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 701px; --smush-placeholder-aspect-ratio: 701\/382;\" \/><figcaption>Figure 1<\/figcaption><\/figure>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong><strong>What is Ransomware?<\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware is a sort of crypto virology malware that threatens to publish or permanently limit access to the victim&#8217;s data unless a ransom is paid. While some ransomware locks the system in a way that is easy to undo for a trained user, more powerful virus employs a tactic known as crypto viral extortion. It encrypts the victim&#8217;s files, rendering them inaccessible, and demands a ransom to decrypt them.<\/p>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong>About the Cyberattack<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kojima Industries, a supplier of&nbsp;plastic parts and electronic components for Toyota was the target of this attack. The supplier confirmed Tuesday morning that it shut down its server on Sunday, February 27 after discovering malware and a threatening message, which could indicate it had been the target of a ransomware attack.<sup>3<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An official close to Kojima Industries&nbsp;told&nbsp;<a href=\"https:\/\/asia.nikkei.com\/\">Nikkei<\/a>: &#8220;It is true that we have been hit by a cyberattack. We are still confirming the damage and we are hurrying to respond, with the top priority of resuming Toyota&#8217;s production system as soon as possible.&#8221;<sup>4<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The company said that it is still investigating the origin of the attack, as well as the damage caused to its system, &#8220;Toyota representatives and cybersecurity experts are at Kojima Industries to determine the cause and how to restore&#8221;<sup>4<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You might be wondering, why does a cyberattack on the supplier effects the Toyota Motor Company? It is because Toyota&#8217;s direct suppliers are all linked to the automaker&#8217;s \u2018kanban\u2019 just-in-time production control system, which causes the threat of the attack at Kojima to spill over into Toyota\u2019s IT systems.<\/p>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong>Impact of the Cyberattack<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Halting operations across Japan for 24 hours is estimated to impact about 5% of output for the month, which makes up to roughly 13,000 vehicles. Toyota subsidiaries, Daihatsu Motors and Hino Motors also had to stop production, but the exact impact on them is not clear.<sup>5<\/sup><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1024x529.jpg\" alt=\"\" class=\"wp-image-2295 lazyload\" width=\"435\" height=\"224\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1024x529.jpg 1024w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-300x155.jpg 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-768x397.jpg 768w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1536x794.jpg 1536w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1-1568x811.jpg 1568w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Picture1.jpg 1787w\" data-sizes=\"(max-width: 435px) 100vw, 435px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 435px; --smush-placeholder-aspect-ratio: 435\/224;\" \/><figcaption>Figure 2<\/figcaption><\/figure>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong>Russia Link?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack occurred just after Japan joined Western allies in condemning Russia for invading Ukraine. On the weekend, Japanese Prime Minister Fumio Kishida stated that Japan would join the United States and other countries in barring access to the SWIFT international payment system for selected Russian banks. He also said that Japan would provide $100 million in emergency relief to Ukraine. However, it is unclear whether the two incidents are connected.<sup>6<\/sup><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Kishida, the government will investigate the event and determine whether Russia was involved in the cyberattack. \u201cRegarding any connection with Russia, it is hard to answer until we have conducted thorough checks.\u201d<sup>3<\/sup><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.25.36-AM-1024x771.png\" alt=\"\" class=\"wp-image-2296 lazyload\" width=\"664\" height=\"500\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.25.36-AM-1024x771.png 1024w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.25.36-AM-300x226.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.25.36-AM-768x578.png 768w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/03\/Screen-Shot-2022-03-03-at-3.25.36-AM.png 1412w\" data-sizes=\"(max-width: 664px) 100vw, 664px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 664px; --smush-placeholder-aspect-ratio: 664\/500;\" \/><figcaption>Figure 3<\/figcaption><\/figure>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong>How to respond to Ransomware Attack<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">=&gt; Report to the authorities<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OR<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">=&gt; Decide whether to pay the ransom<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OR<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">=&gt; Consider the following steps to help remove and reduce the spread of ransomware.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Take your devices offline to stop the ransomware from spreading to other connected devices.<\/li><li>Use the information in the ransom note (e.g. listed URLs) and the new file extensions your encrypted files inherited, to research possible reoccurring attacks and identify the ransomware.<\/li><li>Use the online decryption tool to remove the ransomware from your devices, which should decrypt your files and make them accessible.<\/li><li>If there is no decryption tool available online for your strain of ransomware, safely wipe your device and reinstall the operating system.<\/li><li>Analyze your backup files and ensure they are free of the ransomware or any other malware. Store your backups offline to mitigate the chance of the ransomware infecting your backup files.<\/li><li>Apply any available updates to your devices, hardware, and software. Patch your operating system and ensure all anti-virus, anti-malware, and firewall software are up to date.<\/li><li>Reset credentials including passwords on all systems, devices, and accounts.<\/li><\/ol>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\"><strong>References:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li><a href=\"https:\/\/www.itsecurityguru.org\/2022\/03\/01\/toyota-hit-with-ransomware-attack-stops-production\/\">https:\/\/www.itsecurityguru.org\/2022\/03\/01\/toyota-hit-with-ransomware-attack-stops-production\/<\/a><\/li><li><a href=\"https:\/\/www.cshub.com\/attacks\/news\/iotw-car-production-halted-by-toyota-after-suspected-cyber-attack\">https:\/\/www.cshub.com\/attacks\/news\/iotw-car-production-halted-by-toyota-after-suspected-cyber-attack<\/a><\/li><li><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2022-02-28\/toyota-to-halt-plants-after-cyberattack-on-supplier-nikkei-says\">https:\/\/www.bloomberg.com\/news\/articles\/2022-02-28\/toyota-to-halt-plants-after-cyberattack-on-supplier-nikkei-says<\/a><\/li><li><a href=\"https:\/\/asia.nikkei.com\/Spotlight\/Supply-Chain\/Toyota-halts-operations-at-all-Japan-plants-due-to-cyberattack\">https:\/\/asia.nikkei.com\/Spotlight\/Supply-Chain\/Toyota-halts-operations-at-all-Japan-plants-due-to-cyberattack<\/a><\/li><li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/toyota-halts-production-after-reported-cyberattack-on-supplier\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/toyota-halts-production-after-reported-cyberattack-on-supplier\/<\/a><\/li><li><a href=\"https:\/\/www.reuters.com\/business\/autos-transportation\/toyota-suspends-all-domestic-factory-operations-after-suspected-cyber-attack-2022-02-28\/?taid=621cbb9ced681a0001a16ec6&amp;utm_campaign=trueAnthem:+Trending+Content&amp;utm_medium=trueAnthem&amp;utm_source=twitter\">https:\/\/www.reuters.com\/business\/autos-transportation\/toyota-suspends-all-domestic-factory-operations-after-suspected-cyber-attack-2022-02-28\/?taid=621cbb9ced681a0001a16ec6&amp;utm_campaign=trueAnthem:+Trending+Content&amp;utm_medium=trueAnthem&amp;utm_source=twitter<\/a><\/li><li>Figure 1:&nbsp;<a href=\"https:\/\/www.itsecurityguru.org\/2022\/03\/01\/toyota-hit-with-ransomware-attack-stops-production\/\">https:\/\/www.itsecurityguru.org\/2022\/03\/01\/toyota-hit-with-ransomware-attack-stops-production\/<\/a><\/li><li>Figure 2:&nbsp;<a href=\"https:\/\/www.istockphoto.com\/photo\/a-red-arrow-probably-from-a-computer-chart-pointing-down-gm463750989-33309970\">https:\/\/www.istockphoto.com\/photo\/a-red-arrow-probably-from-a-computer-chart-pointing-down-gm463750989-33309970<\/a><\/li><li>Figure 3:&nbsp;<em><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2022-02-28\/toyota-to-halt-plants-after-cyberattack-on-supplier-nikkei-says\">https:\/\/www.bloomberg.com\/news\/articles\/2022-02-28\/toyota-to-halt-plants-after-cyberattack-on-supplier-nikkei-says<\/a><\/em><\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Toyota Motor Company suspended all factories in Japan on Tuesday, March 1,&nbsp;&nbsp;after a critical supplier suffered ransomware that disrupted the automaker&#8217;s parts supply management system. The Japanese automobile giant had to suspend 28 production lines at 14 factories across Japan for 24 hours.1 In a statement on March 1, 2022, Toyota said: \u201cWe would like &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/03\/ransomware-attack-on-toyota-motors-halts-production-across-japan\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Ransomware attack on Toyota Motors, halts production across Japan&#8221;<\/span><\/a><\/p>\n","protected":false},"author":372,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[16,47],"class_list":["post-2291","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","tag-cpsc329","tag-ransomware","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Arhum Ladak","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/arhum-ladak\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/372"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2291"}],"version-history":[{"count":6,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2291\/revisions"}],"predecessor-version":[{"id":2322,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2291\/revisions\/2322"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}