Current:Home > MarketsNissan data breach exposed Social Security numbers of thousands of employees -RiskWatch
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-22 10:29:42
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (38)
Related
- Jamie Foxx gets stitches after a glass is thrown at him during dinner in Beverly Hills
- Some Muslim Americans Turn To Faith For Guidance On Abortion
- When gun violence ends young lives, these men prepare the graves
- Meadow Walker Shares Heartwarming Signs She Receives From Late Dad Paul Walker
- Current, future North Carolina governor’s challenge of power
- A police dog has died in a hot patrol car for the second time in a week
- Starbucks to pay $25 million to former manager Shannon Phillips allegedly fired because of race
- Farmers, Don’t Count on Technology to Protect Agriculture from Climate Change
- Elon Musk's skyrocketing net worth: He's the first person with over $400 billion
- Ryan Shazier was seriously injured in an NFL game. He has advice for Damar Hamlin
Ranking
- Why Sean "Diddy" Combs Is Being Given a Laptop in Jail Amid Witness Intimidation Fears
- UV nail dryers may pose cancer risks, a study says. Here are precautions you can take
- COVID-19 is a leading cause of death among children, but is still rare
- What is the Hatch Act — and what count as a violation?
- Backstage at New York's Jingle Ball with Jimmy Fallon, 'Queer Eye' and Meghan Trainor
- Ultra rare and endangered sperm whale pod spotted off California coast in once a year opportunity
- You Won't Calm Down Over Taylor Swift and Matty Healy's Latest NYC Outing
- Farm Bureau Warily Concedes on Climate, But Members Praise Trump’s Deregulation
Recommendation
A Mississippi company is sentenced for mislabeling cheap seafood as premium local fish
MrBeast YouTuber Chris Tyson Shares New Photo After Starting Hormone Replacement Therapy
Warning for Seafood Lovers: Climate Change Could Crash These Important Fisheries
With less access to paid leave, rural workers face hard choices about health, family
NFL Week 15 picks straight up and against spread: Bills, Lions put No. 1 seed hopes on line
Helen Mirren Brings the Drama With Vibrant Blue Hair at Cannes Film Festival 2023
How Trump’s ‘Secret Science’ Rule Would Put Patients’ Privacy at Risk
Police officer who shot 11-year-old Mississippi boy suspended without pay