Current:Home > MarketsNissan data breach exposed Social Security numbers of thousands of employees -Trailblazer Capital Learning
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-19 14:15:30
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (158)
Related
- Taylor Swift Eras Archive site launches on singer's 35th birthday. What is it?
- Pilot swims to shore with dog after plane crashes into Pacific Ocean near Los Angeles
- Justice Department nears settlement with Larry Nassar victims over FBI failures
- Zendaya Addresses Fate of Euphoria Season 3
- A White House order claims to end 'censorship.' What does that mean?
- How many rounds are in the NFL draft? Basic info to know for 2024 event
- 10 detained in large-scale raid in Germany targeting human smuggling gang that exploits visa permits
- Why Even Stevens' Christy Carlson Romano Refuses to Watch Quiet on Set
- Dick Vitale announces he is cancer free: 'Santa Claus came early'
- Unlike Deion Sanders, Nebraska coach Matt Rhule has been prolific in off-campus recruiting
Ranking
- Finally, good retirement news! Southwest pilots' plan is a bright spot, experts say
- California woman falls 140 feet to her death while hiking on with husband, daughter in Sedona
- NASCAR's Bubba Wallace and Wife Amanda Expecting First Baby
- Justice Department nears settlement with Larry Nassar victims over FBI failures
- DeepSeek: Did a little known Chinese startup cause a 'Sputnik moment' for AI?
- Report of gunshot prompts lockdown at Grand Forks Air Force Base in North Dakota
- Pilot swims to shore with dog after plane crashes into Pacific Ocean near Los Angeles
- Psst, H&M's Sale Section is Filled With Trendy & Affordable Styles That Are Up to 72% Off Right Now
Recommendation
What to know about Tuesday’s US House primaries to replace Matt Gaetz and Mike Waltz
Q&A: Phish’s Trey Anastasio on playing the Sphere, and keeping the creativity going after 40 years
Appeals court leaves temporary hold on New Jersey’s county line primary ballot design in place
'Too drunk to fly': Intoxicated vultures rescued in Connecticut, fed food for hangover
Nearly 400 USAID contract employees laid off in wake of Trump's 'stop work' order
Climate change concerns grow, but few think Biden’s climate law will help, AP-NORC poll finds
Cardi B Details NSFW Way She Plans to Gain Weight After Getting Too Skinny
Megan Fox's Makeup-Free Selfie Proves She Really Is God's Favorite