Current:Home > MyNissan data breach exposed Social Security numbers of thousands of employees -TradeWise
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 06:47:05
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (918)
Related
- Warm inflation data keep S&P 500, Dow, Nasdaq under wraps before Fed meeting next week
- Some Georgia Republicans who sank an education voucher bill in 2023 aren’t changing their minds
- 3 years after Jan. 6 Capitol riot, Trump trial takes center stage, and investigators still search for offenders
- 'A profound desecration': Navajo Nation asks NASA to delay moon mission with human remains
- San Francisco names street for Associated Press photographer who captured the iconic Iwo Jima photo
- Global food prices declined from record highs in 2022, the UN says. Except for these two staples
- Stanley cups have people flooding stores and buying out shops. What made them so popular?
- Is 'the spark' a red flag? Sometimes. Experts say look for this in a relationship instead
- New data highlights 'achievement gap' for students in the US
- Microsoft adding new PC button in its first significant keyboard change in decades
Ranking
- Paris Hilton, Nicole Richie return for an 'Encore,' reminisce about 'The Simple Life'
- Wisconsin’s Democratic governor says Biden must visit battleground state often to win it
- Civil rights lawsuit filed over 2022 Philadelphia fire that killed 9 children and 3 adults
- Gigantic spider found in Australia, dubbed Hercules, is a record-setter
- 'Most Whopper
- Actor Christian Oliver Shared Photo From Paradise 3 Days Before Fatal Plane Crash
- Rascal Flatts guitarist Joe Don Rooney sets 'record straight' on transitioning rumors
- Agencies release plans for moving hotel-dwelling Maui fire survivors into long-term housing
Recommendation
The FBI should have done more to collect intelligence before the Capitol riot, watchdog finds
Maine man injured in crash is shocked by downed power line
New FAFSA form, still difficult to get to, opens for longer hours. Here are the details.
Texas Tech says Pop Isaacs is ‘in good standing’ after report of lawsuit alleging sexual assault
Trump suggestion that Egypt, Jordan absorb Palestinians from Gaza draws rejections, confusion
100 New Jersey firefighters battle blaze at former Singer sewing machine factory
Blaine Luetkemeyer, longtime Missouri Republican congressman, won’t seek reelection
What to know about 'Bluey' new episodes streaming soon on Disney+