Current:Home > MyNissan data breach exposed Social Security numbers of thousands of employees -Infinite Edge Learning
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-16 20:56:01
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (61395)
Related
- Who are the most valuable sports franchises? Forbes releases new list of top 50 teams
- Michigan State football coach Mel Tucker suspended without pay amid sexual misconduct investigation
- Several wounded when gunmen open fire on convoy in Mexican border town
- Virginia governor pardons man whose arrest at a school board meeting galvanized conservatives
- Backstage at New York's Jingle Ball with Jimmy Fallon, 'Queer Eye' and Meghan Trainor
- Misery Index Week 2: Alabama has real problems, as beatdown by Texas revealed
- Lil Nas X documentary premiere delayed by bomb threat at Toronto International Film Festival
- Turkey cave rescue of American Mark Dickey like Himalayan Mountain climbing underground, friend says
- Sam Taylor
- Officials search for grizzly bear that attacked hunter near Montana's Yellow Mule Trail
Ranking
- Federal court filings allege official committed perjury in lawsuit tied to Louisiana grain terminal
- Residents mobilize in search of dozens missing after Nigeria boat accident. Death toll rises to 28
- Pearl Jam postpones Indiana concert 'due to illness': 'We wish there was another way around it'
- Moroccan soldiers and aid teams battle to reach remote, quake-hit towns as toll rises past 2,400
- Travis Hunter, the 2
- Age and elected office: Concerns about performance outweigh benefits of experience
- Europe’s economic outlook worsens as high prices plague consumer spending
- Laurel Peltier Took On Multi-Million Dollar Private Energy Companies Scamming Baltimore’s Low-Income Households, One Victim at a Time
Recommendation
Nearly half of US teens are online ‘constantly,’ Pew report finds
Spanish soccer president Luis Rubiales resigns after nonconsensual kiss at Women’s World Cup final
Oprah Winfrey: Envy is the great destroyer of happiness
South Korean media: North Korean train presumably carrying leader Kim Jong Un departed for Russia
New Zealand official reverses visa refusal for US conservative influencer Candace Owens
Misery Index Week 2: Alabama has real problems, as beatdown by Texas revealed
Hawaii volcano Kilauea erupts after nearly two months of quiet
Niger junta accuses France of amassing forces for a military intervention after the coup in July