Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Toyota T-Connect Key Exposure 2022: How an Access…
Breach analysis Incident: 10 Oct 2022

Toyota T-Connect Key Exposure 2022: How an Access Key Sat on Public GitHub for Five Years

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: NHI
Attack route: Leaked secret Identities: Secret or password
On this page

In October 2022, Toyota disclosed that the email addresses and customer management numbers of 296,019 T-Connect customers could have been accessed by anyone for almost five years. A development subcontractor building the T-Connect website had uploaded part of its source code to a public GitHub repository in December 2017. The code contained an access key to the data server that stored those customer records. Nobody noticed until 15 September 2022, when Toyota made the repository private; it changed the server's access key two days later. Toyota's investigation could neither confirm nor rule out that someone had used the key: "we cannot confirm access by a third party... at the same time, we cannot completely deny it." Names, phone numbers and card data were not on that server.

Key takeaways

  • A subcontractor published part of the T-Connect website's source code to public GitHub in December 2017, including an access key to a customer data server.
  • The key stayed exposed until 15 September 2022, almost five years, and was changed on 17 September 2022.
  • Up to 296,019 customers' email addresses and customer management numbers were at risk, according to Toyota.
  • Toyota's investigation could not confirm or rule out access by a third party, so this is an exposure with no confirmed misuse.
  • The identity lesson: a long-lived key in code has no natural end date, so an exposure can last years unless someone is scanning for it.

At a glance

OrganisationToyota Motor Corporation (T-Connect connected car service); a development subcontractor
WhenExposed from December 2017 to 15 September 2022; key changed 17 September 2022; disclosed October 2022
AttackerNone identified; Toyota could not confirm or rule out third-party access
Entry pointT-Connect website source code published to a public GitHub repository by a subcontractor
Identities abusedAn access key to the data server holding T-Connect customer email addresses and management numbers
Impact296,019 customers' email addresses and customer management numbers exposed to possible access; no confirmed misuse
CategoryNHI. Incident class: exposure (credential public for five years, no confirmed misuse)

What happened

T-Connect is Toyota's connected car service, which links owners' smartphones to their vehicles for features such as navigation, remote start and smartphone digital keys. According to Toyota's statement, reported by TechCrunch and The Register, a subcontractor developing the T-Connect website uploaded part of the site's source code to a public GitHub repository in December 2017. The code contained an access key to a server storing customer email addresses and customer management numbers, which made that server reachable by anyone who found the key.

The repository sat unnoticed until 15 September 2022. Toyota then made it private and, on 17 September 2022, changed the data server's access key. BleepingComputer, citing Toyota's notice, reported that this "made it possible for an unauthorized third party to access the details of 296,019 customers between December 2017 and September 15, 2022." Toyota said customer names, credit card data and phone numbers were not stored in the exposed database.

Toyota's security investigation could not settle whether the key had been used. "As a result of an investigation by security experts, although we cannot confirm access by a third party based on the access history of the data server where the customer's email address and customer management number are stored, at the same time, we cannot completely deny it," Toyota said, as quoted by TechCrunch. It advised T-Connect users who registered between July 2017 and September 2022 to watch for Toyota-themed phishing emails, and blamed the development subcontractor while accepting responsibility for the mishandling.

Timeline

DateEvent
December 2017A subcontractor uploads part of the T-Connect website source code, including a data server access key, to a public GitHub repository.
15 September 2022Toyota discovers the repository and restricts access to it.
17 September 2022Toyota changes the data server's access key.
10 October 2022Toyota's disclosure is reported by BleepingComputer, followed by The Register and TechCrunch.

How it happened: the identity attack path

  1. Code published by a third party. A development subcontractor pushed part of the T-Connect website code to a public GitHub repository.
  2. Key embedded in code. The code included a live access key to the customer data server.
  3. No detection for five years. Neither Toyota nor the subcontractor found the public repository until September 2022.
  4. Uncertain access. Server access history did not let Toyota confirm or rule out use of the key.
  5. Containment. The repository was made private and the key changed two days later.

Impact

  • Exposed: email addresses and customer management numbers of 296,019 T-Connect customers.
  • Not exposed: names, phone numbers and card data, which were not stored on the server.
  • Misuse: not confirmed and not ruled out; customers were warned about phishing.

What this means for NHI governance

This exposure lasted almost five years because the key never expired and nobody was looking for it. A long-lived server key in source code is a standing credential with no owner watching it. When the code went public, the key went with it, and the only thing that ended the exposure was someone happening to notice.

The case also shows the third-party dimension. The code was published by a subcontractor, outside Toyota's own repositories, yet the key opened Toyota's customer data. Organisations need secret scanning that covers public code mentioning their domains and brands, contracts that require suppliers to handle secrets properly, and keys that are short-lived or scoped so an old leak stops working on its own. See our Secrets Management Guide and Third-Party Access Guide.

Recommendations

  • Keep access keys out of source code. Load them from a secrets manager at runtime. See our Secrets Management Guide.
  • Monitor public code for your secrets. Scan public GitHub and other hosts for keys, domains and identifiers linked to your organisation, including code published by suppliers.
  • Rotate keys on a schedule. Keys that expire or are rotated regularly limit how long any leak can be exploited.
  • Put secret handling in supplier contracts. Require subcontractors to use your secrets tooling and to report exposures. See the Third-Party Access Guide.
  • Log data server access in detail. Good access history lets you prove whether an exposed key was used. See the Leaked Credential Response Playbook.

Frequently asked questions

What happened in the Toyota T-Connect data leak?

A subcontractor published part of the T-Connect website's source code to public GitHub in December 2017. It included an access key to a server holding 296,019 customers' email addresses and customer management numbers. The exposure lasted until September 2022.

Was Toyota customer data stolen?

Toyota said it could neither confirm nor rule out access by a third party. Names, phone numbers and card data were not on the exposed server.

How long was the Toyota access key exposed?

Almost five years, from December 2017 until Toyota made the repository private on 15 September 2022. It changed the key on 17 September 2022.

New York Times Breach 2024 · Microsoft SAS Token Exposure 2023 · Secrets Management Guide · Third-Party Access Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Exposures like this are found years late because nobody owns the key. We help organisations find secrets in their own and their suppliers' code, assign owners and set rotation so leaks expire. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org