Denso said attackers accessed its network in Germany on March 10, 2022. The Japanese automotive supplier disconnected compromised devices and reported that production continued normally, without disruption. The ransomware group Pandora claimed it stole 1.4 terabytes of data, but that figure was an attacker allegation, not an independently verified measurement.
What happened to Denso?
In a statement reported by SecurityWeek on March 14, 2022, Denso said it had detected unauthorized access to its German network. The company disconnected network connections for devices it considered compromised. Its public account described containment at the affected network—not a shutdown of its factories.
As an Amazon Associate I earn from qualifying purchases.
Pandora posted a file list and images of documents as purported evidence of the breach. SecurityWeek reported that the list appeared to cover tens of thousands of documents, spreadsheets, presentations and images, with references to customers and employees. Those materials were presented by the attackers; their appearance does not independently establish how much data was accessed or taken.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteDid the attack stop car production?
No production interruption was reported at the time. Denso said its plants continued operating normally after it disconnected compromised devices. That establishes the immediate operational impact described in the company’s statement; it does not establish what happened in every system or what later remediation involved.
#1 Best Overall
The distinction matters for automotive suppliers: a cyber incident can expose business-sensitive information without halting manufacturing. Potentially affected customer, employee or engineering data can create risks for companies and people even when production lines keep running. The public statements cited here do not provide a final forensic account of what information, if any, was ultimately confirmed stolen.
Who claimed responsibility, and how much data did the group say it stole?
Pandora claimed responsibility and alleged that it had stolen 1.4 TB of Denso data. SecurityWeek reported the claim, and ENISA’s transport threat landscape also summarized it. Neither makes the figure an audited total: it remains a number asserted by the attackers.
SecurityWeek cited researchers who suspected Pandora was a rebranding of Rook ransomware, but that attribution was not definitive. Denso had also appeared on Rook’s leak website in December 2021, accompanied by a separate 1.1 TB theft claim. Neither the Rook attribution nor that earlier amount was confirmed by Denso. The available reporting does not establish that Denso paid a ransom.
A March 2022 Hivepro advisory described Pandora as a ransomware gang that targeted automotive, manufacturing, technology and finance organizations, and listed Germany, Japan and the United States among its target locations. That profile provides context for the group’s claimed activity, not independent confirmation of the Denso allegations.
Rank #3
What does the incident show about protecting automotive suppliers?
Denso’s reported response focused on disconnecting compromised devices, while the breach claims concerned data. Those are related but different security problems: controlling network access can help contain an intrusion, while protecting sensitive information requires attention to the data itself, including what can be read or used if an attacker reaches it.
Shane Curran, CEO of Irish encryption firm Evervault, said after Pandora’s claim: “With the Pandora hacking group claiming 1.4TB of data has been stolen, it’s imperative that manufacturers secure their data, not just their networks.” The practical implication is broader than this incident: supplier security has to account for both factory continuity and the confidentiality of customer, employee and engineering information.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




