Current:Home > MyNissan data breach exposed Social Security numbers of thousands of employees -NextGenWealth
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 23:31:58
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (228)
Related
- DoorDash steps up driver ID checks after traffic safety complaints
- Costa Rican soccer player killed in crocodile attack after jumping into river
- Watch PK that ended USWNT's World Cup reign: Alyssa Naeher nearly makes miracle save
- Christmas Tree Shops announces 'last day' sale; closing remaining locations in 16 states
- Travis Hunter, the 2
- Suddenly repulsed by your partner? You may have gotten 'the ick.' Here's what that means.
- U.S. eliminated from Women's World Cup in heartbreaking loss to Sweden
- Bachelor Nation's Kaitlyn Bristowe Taking Social Media Break After Jason Tartick Split
- Where will Elmo go? HBO moves away from 'Sesame Street'
- NASCAR driver Noah Gragson suspended for liking racially insensitive meme on social media
Ranking
- US wholesale inflation accelerated in November in sign that some price pressures remain elevated
- Bachelor Nation's Kaitlyn Bristowe and Jason Tartick Break Up After 4 Years Together
- USWNT ousted from World Cup: Team USA reels from historic loss to Sweden
- 2 people charged in connection with Morgan Bauer's 2016 disappearance in Georgia
- Juan Soto to be introduced by Mets at Citi Field after striking record $765 million, 15
- 3 dead, dozens injured as tour bus carrying about 50 people crashes on Pennsylvania highway
- What happens when a person not mentally competent is unfit for trial? Case spotlights issue
- 2-alarm fire burns at plastic recycling facility near Albuquerque
Recommendation
Sarah J. Maas books explained: How to read 'ACOTAR,' 'Throne of Glass' in order.
At least 2 buildings destroyed in flooding in Alaska’s capital from glacial lake water release
Your HSA isn't just for heath care now. Here are 3 ways it can help you in retirement.
Suddenly repulsed by your partner? You may have gotten 'the ick.' Here's what that means.
Google unveils a quantum chip. Could it help unlock the universe's deepest secrets?
Trucking giant Yellow Corp. declares bankruptcy after years of financial struggles
Ex-Minneapolis officer faces sentencing on a state charge for his role in George Floyd’s killing
In a first, naval officers find huge cache of dynamite in cave-like meth lab run by Mexican drug cartel