Denso said attackers accessed its network in Germany on March 10, 2022. The company disconnected compromised devices and reported that production continued normally. The ransomware group Pandora later claimed it had stolen 1.4 terabytes of data, but that figure was an attacker claim, not an independently verified measurement.
What happened to Denso?
Japanese automotive supplier Denso disclosed that attackers accessed its German network on March 10, 2022. SecurityWeek reported on March 14 that Denso responded by disconnecting network connections for compromised devices. The company said its production activities were not disrupted and its plants continued operating normally.
The reported response was containment: isolating affected devices while keeping production running. The available reporting does not describe a factory shutdown.
Who claimed responsibility, and what did the group say it took?
The cybercrime group Pandora claimed responsibility and alleged it had stolen 1.4 terabytes of Denso data. ENISA’s transport threat landscape also summarized that claim. Neither report established the amount through an independent audit, so it should be treated as Pandora’s allegation rather than a confirmed measure of stolen data.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
SecurityWeek said the attackers published a file list and images of documents as purported proof. The list appeared to cover tens of thousands of documents, spreadsheets, presentations and images, and included references to customers and employees. That material indicates the kinds of files the attackers said they had, but does not by itself verify how much data was taken or establish that every listed file was exfiltrated.
Was Pandora linked to an earlier Denso leak claim?
Researchers cited by SecurityWeek suspected Pandora was a rebranding of the Rook ransomware operation; the connection was not confirmed. Denso had also appeared on Rook’s leak website in December 2021, accompanied by an earlier claim that 1.1 terabytes had been stolen. That earlier theft figure was likewise not confirmed by Denso.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Hivepro’s March 2022 advisory described Pandora as a ransomware gang targeting automotive, manufacturing, technology and finance organizations, and listed Germany, Japan and the United States among its target locations. These descriptions provide context for the group’s reported activity, not a definitive attribution of the Denso incident to Rook.
What did the incident mean for production and the wider supply chain?
Denso’s statement that production continued normally is the clearest reported account of the immediate operational effect. It does not answer every question about possible data exposure. Automotive suppliers handle information connected to customers, employees and manufacturing, so a breach can create confidentiality and supply-chain concerns even when factories remain open.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
The SecurityWeek report described references to customers and employees in the posted file list, but did not establish that those people suffered identity theft, fraud or other harm. The incident reporting cited here also does not establish whether any customer or employee data was misused, whether Denso paid a ransom, or what final forensic conclusions the company reached.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is the practical security lesson?
The case illustrates why keeping production online and protecting sensitive information are related but separate goals. Disconnecting compromised devices can help contain an intrusion without stopping operations; it does not, on its own, show whether data was accessed or copied.
Rank #4
Shane Curran, chief executive of Irish encryption firm Evervault, said: “With the Pandora hacking group claiming 1.4TB of data has been stolen, it’s imperative that manufacturers secure their data, not just their networks.” The distinction matters across a supplier chain: network controls can limit access, while protecting data itself can reduce the consequences if an attacker gets through.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




