Current:Home > ScamsNissan data breach exposed Social Security numbers of thousands of employees -ValueCore
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-21 07:02:18
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (6)
Related
- Trump wants to turn the clock on daylight saving time
- How to clean suede shoes at home without ruining them
- Delta passengers stranded at remote military base after flight diverted to Canada
- Two indicted in Maine cold case killing solved after 15 years, police say
- Bill Belichick's salary at North Carolina: School releases football coach's contract details
- Novelist’s book is canceled after she acknowledges ‘review bombs’ of other writers
- Three gun dealers sued by New Jersey attorney general, who says they violated state law
- Semi-trailer driver dies after rig crashes into 2 others at Indiana toll plaza
- Charges tied to China weigh on GM in Q4, but profit and revenue top expectations
- Her 10-year-old son died in a tornado in Tennessee. Her family's received so many clothing donations, she wants them to go others in need.
Ranking
- Average rate on 30
- Horoscopes Today, December 12, 2023
- Ethiopia arrests former peace minister over alleged links to an outlawed rebel group
- Vikings bench Joshua Dobbs, turn to Nick Mullens as fourth different starting QB this season
- Trump wants to turn the clock on daylight saving time
- Taylor Swift’s Eras Tour Officially Becomes Highest-Grossing Tour Ever
- 2023 in other words: AI might be the term of the year, but consider these far-flung contenders
- Trump's defense concludes its case in New York fraud trial
Recommendation
Person accused of accosting Rep. Nancy Mace at Capitol pleads not guilty to assault charge
North Korean and Russian officials discuss economic ties as Seoul raises labor export concerns
South Dakota vanity plate restrictions were unconstitutional, lawsuit settlement says
Girl dinner, the Roman Empire: A look at TikTok's top videos, creators and trends of 2023
'Vanderpump Rules' star DJ James Kennedy arrested on domestic violence charges
Three gun dealers sued by New Jersey attorney general, who says they violated state law
How the remixed American 'cowboy' became the breakout star of 2023
Are the products in your shopping cart real?