Current:Home > MarketsNissan data breach exposed Social Security numbers of thousands of employees -Secure Growth Solutions
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-16 17:57:45
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (15)
Related
- Immigration issues sorted, Guatemala runner Luis Grijalva can now focus solely on sports
- Biden declares major disaster area in southeast New Mexico due to historic flooding
- Who’s Running in the Big Money Election for the Texas Railroad Commission?
- Alex Ovechkin goal tracker: How far is Capitals star behind Wayne Gretzky's record?
- 'Stranger Things' prequel 'The First Shadow' is headed to Broadway
- Do all Americans observe daylight saving time? Why some states and territories don't.
- Dawson's Creek's James Van Der Beek Shares Colorectal Cancer Diagnosis
- Hindered Wildfire Responses, Costlier Agriculture Likely If Trump Dismantles NOAA, Experts Warn
- Olympic women's basketball bracket: Schedule, results, Team USA's path to gold
- Shootings kill 2 and wound 7 during Halloween celebrations in Orlando
Ranking
- 'Stranger Things' prequel 'The First Shadow' is headed to Broadway
- Harris and Trump will both make a furious last-day push before Election Day
- Endangered Bats Have Slowed, But Not Stopped, a Waterfront Mega-Development in Charleston. Could Flood Risk?
- Sister Wives’ Janelle Brown Confronts Ex Kody Brown About Being Self-Absorbed” During Marriage
- Angelina Jolie nearly fainted making Maria Callas movie: 'My body wasn’t strong enough'
- Longtime music director at Michigan church fired for same-sex marriage
- AP Top 25: Oregon a unanimous No. 1 ahead of 1st CFP rankings, followed by Georgia, Ohio State
- Chris Olave injury update: Saints WR suffers concussion in Week 9 game vs. Panthers
Recommendation
Family of explorer who died in the Titan sub implosion seeks $50M-plus in wrongful death lawsuit
A Rural Arizona Community May Soon Have a State Government Fix For Its Drying Wells
The Futures of Right Whales and Lobstermen Are Entangled. Could High-Tech Gear Help Save Them Both?
Teddi Mellencamp’s Estranged Husband Edwin Arroyave Shares Post About “Dark Days” Amid Divorce
IOC's decision to separate speed climbing from other disciplines paying off
Nvidia replaces Intel on the Dow index in AI-driven shift for semiconductor industry
The man who took in orphaned Peanut the squirrel says it’s ‘surreal’ officials euthanized his pet
Pacific and Caribbean Island Nations Call for the First Universal Carbon Levy on International Shipping Emissions