# Insecure Toyota CRM exposed Mexican customer information

DevFeed: [Insecure Toyota CRM exposed Mexican customer information](<https://devfeed.tech/articles/insecure-toyota-crm-exposed-mexican-customer-information-32603.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/03/06/toyota-c360-hack/>)

Author: Eaton

Published: 2023-03-06T17:52:27Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [data](<https://devfeed.tech/topics/data.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [data](<https://devfeed.tech/tags/data.md>), [security](<https://devfeed.tech/tags/security.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

## AI overview

A security writeup describes how Toyota's C360 CRM for Mexican customers could be accessed by bypassing its corporate login and switching a development app to the production API. The exposed unauthenticated API returned customer information, and Toyota fixed the issue after responsible disclosure.

## Source excerpt

Breaking into a Toyota CRM and exploiting it to view customer information.