Current:Home > FinanceNissan data breach exposed Social Security numbers of thousands of employees -Prime Capital Blueprint
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-11 12:15:04
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (164)
Related
- Average rate on 30
- Wayne Kramer, co-founder of revolutionary rock band the MC5, dead at 75
- Federal authorities investigate suspected arson at offices of 3 conservative groups in Minnesota
- Providence approves first state-sanctioned safe injection site in Rhode Island
- Why Sean "Diddy" Combs Is Being Given a Laptop in Jail Amid Witness Intimidation Fears
- Lincoln University and the murky world of 'countable opponents' in college sports
- Lawyers for Idaho murders suspect Bryan Kohberger seek change of trial venue, citing inflammatory publicity
- NFL veteran QB Teddy Bridgewater named head coach at alma mater, Miami Northwestern
- Average rate on 30
- Federal authorities investigate suspected arson at offices of 3 conservative groups in Minnesota
Ranking
- The company planning a successor to Concorde makes its first supersonic test
- Want to run faster? It comes down to technique, strength and practice.
- Desmond Gumbs juggles boxing deals, Suge Knight project while coaching Lincoln football
- Her son was a school shooter. Now, a jury will decide if Jennifer Crumbley is guilty, too.
- 'Vanderpump Rules' star DJ James Kennedy arrested on domestic violence charges
- Formula One champion Lewis Hamilton leaves Mercedes to join Ferrari in surprise team switch
- Oklahoma rattled by shallow 5.1 magnitude earthquake
- Will the Moody Landfill Fire Ever Be Extinguished? The EPA Isn’t So Sure.
Recommendation
See you latte: Starbucks plans to cut 30% of its menu
Shop Amazon’s Epic Baby Sale & Stock Up on Highly-Rated Essentials from Medela, Dr. Brown's & More
Cher and Boyfriend Alexander Edwards Enjoy Date Night at Pre-Grammys Party After Rekindling Romance
Delta and Amex hike credit card fees while enhancing perks. Here's what to know.
IRS recovers $4.7 billion in back taxes and braces for cuts with Trump and GOP in power
Towering over the Grammys is a Los Angeles high-rise tagged with 27 stories of graffiti
Joe Rogan signs new multiyear Spotify deal that allows him to stream on other services
Ex-Red Sox GM Theo Epstein returns to Fenway Sports Group as part owner, senior advisor