Current:Home > InvestNissan data breach exposed Social Security numbers of thousands of employees -Core Financial Strategies
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-19 13:29:06
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (17)
Related
- Dick Vitale announces he is cancer free: 'Santa Claus came early'
- Boxer Lin Yu-Ting, targeted in gender eligibility controversy, to fight for gold
- SUV crash that killed 9 family members followed matriarch’s 80th birthday celebration in Florida
- Rapper Nelly is arrested for suspected drug possession at St. Louis-area casino
- Pressure on a veteran and senator shows what’s next for those who oppose Trump
- USA women's basketball live updates at Olympics: Start time vs Nigeria, how to watch
- Connie Chiume, South African 'Black Panther' actress, dies at 72
- New York City plaques honoring author Anaïs Nin and rock venue Fillmore East stolen for scrap metal
- Jamie Foxx gets stitches after a glass is thrown at him during dinner in Beverly Hills
- Former Milwaukee hotel workers charged with murder after video shows them holding down Black man
Ranking
- Woman dies after Singapore family of 3 gets into accident in Taiwan
- Drones warned New York City residents about storm flooding. The Spanish translation was no bueno
- IOC's decision to separate speed climbing from other disciplines paying off
- British golfer Charley Hull blames injury, not lack of cigarettes, for poor Olympic start
- North Carolina justices rule for restaurants in COVID
- USA's Quincy Hall wins gold medal in men’s 400 meters with spectacular finish
- Breaking at 2024 Paris Olympics: No, it's not called breakdancing. Here's how it works
- Daughter of Utah death row inmate navigates complicated dance of grief and healing before execution
Recommendation
House passes bill to add 66 new federal judgeships, but prospects murky after Biden veto threat
'I'm a monster': Utah man set for execution says he makes no excuses but wants mercy
Utah man who killed woman is put to death by lethal injection in state’s first execution since 2010
Hidden Home Gems From Kohl's That Will Give Your Space a Stylish Refresh for Less
'Most Whopper
USA men's volleyball mourns chance at gold after losing 5-set thriller, will go for bronze
'I'm a monster': Utah man set for execution says he makes no excuses but wants mercy
Big Lots store closures could exceed 300 nationwide, discount chain reveals in filing