CSIDB logo
Incident

Denso

Incident posture

Attack window
Mar 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
Denso
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A global automotive components supplier experienced unauthorized network access at its German operations, prompting the company to terminate the connection upon detection. The Pandora ransomware group claimed responsibility, alleging theft of 1.4 terabytes of data including purchase orders, technical specifications, and sales records. Forensic experts assisted the investigation, with no reported operational disruptions to manufacturing facilities or other sites. Authorities were notified, and the organization publicly committed to enhancing security measures following the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 10, 2022, automotive component supplier Denso detected unauthorized third-party access to its network in Germany, prompting immediate disconnection of the affected systems. The company, a global supplier to major manufacturers including Toyota, Honda, General Motors, and Ford, confirmed the breach four days later on March 14. Denso stated the intrusion was isolated to its German operations with no impact on other facilities, production plants, or manufacturing schedules. Forensic experts were engaged to investigate the incident, and local authorities were notified. The company publicly apologized for concerns caused by the breach and committed to strengthening security measures to prevent recurrence. At the time of confirmation, Denso had not disclosed specific technical details about the attack vector or the full scope of compromised systems.

The Pandora ransomware group claimed responsibility for the attack, listing Denso on its data leak site and alleging theft of 1.4 terabytes of data. Samples published on the leak site included a redacted purchase order, technical component documentation, and sales files, indicating exfiltration of operational and commercial records. Pandora’s tactics aligned with standard ransomware operations involving data theft and encryption, with leak threats serving as leverage for extortion. Denso did not confirm whether ransomware was deployed or if data encryption occurred. The company’s public statements emphasized containment of the breach to German networks and maintained no disruption to its $44.6 billion global operations. No customer or supply chain impacts were reported, and Denso did not disclose whether negotiations with threat actors occurred or whether data disclosures followed the initial claim.

Sources

Sources available to members: 1 source.

CSIDB