Online Reputation and Corporate Cybersecurity: Allies and Enemies: The Toyota Case

21/09/2012
|
The Attack Against Toyota’s Cybersecurity and Online Reputation: Scandal

Online Reputation and Corporate Security: Allies and Enemies; this morning we read from Douglas Gray, Chief of Security for the U.S. Army, that Toyota has been the victim of a hacking attack by a former employee of the company.

Toyota has reported one of its former employees for allegedly hacking its computer systems after being dismissed; a lawsuit was filed by the FBI. The disgruntled former worker registered the site www.toyotasupplier.com and ordered the server to stop providing service.

The worker was accused of computer piracy and attacking PCs; the complaint, filed as mentioned by the FBI, was against Ibrahimshah Shahulhameed of Georgetown, Kentucky.

Attack on a Toyota Internal Community

The attack was based on a denial of service from www.toyotasupplier.com, a community that Toyota uses to communicate with vendors worldwide. This reminds us of two absolutely basic elements in the life of a company, especially when the reputation department is involved. On one hand, the custody of the database—I will leave you an example of namechk custody (databases where the company maintains custody and ownership of users and passwords for various online spaces; the systems department must be able to access these accounts as an administrator at any time).

On the other hand, the danger of spokesmanship within communities: what to do when a community manager leaves and takes access to the communities with them, or as we have experienced in some cases with clients, when that person was responsible for systems, hosting management, domains…

The ruling has been in favor of Toyota, and the worker has also been dismissed for harassing employees working on the Toyota account. Shahulhameed was notified by email this morning.

Toyota also alleges that Shahulhameed may have copied, downloaded, and disseminated trade secrets and proprietary information, including pricing information, data quality tests, and data test parts.

The digital forensics team responsible for this case examined the employee’s equipment and determined that Shahulhameed spent nearly six hours inside the Toyota computer system’s security server, resulting in an estimated 3,000 hours of work at 5,000 euros for investigation time, system restoration, and fixing the problems created by the hacking.

Once again, we want to emphasize the importance of considering aspects related to the following in an online reputation plan:

  • cybersecurity in social media
  • Criminal law, ICT law, and legal tech
  • The role of a community manager as a spokesperson
  • online reputation management following a cybersecurity attack on the company

Digital Identity

Methods for analyzing and
assessing online
reputation damage