Current:Home > FinanceNissan data breach exposed Social Security numbers of thousands of employees -Prime Capital Blueprint
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-12 14:14:10
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (8)
Related
- US wholesale inflation accelerated in November in sign that some price pressures remain elevated
- Lapchick lauds NBA’s hiring practices, initiatives in annual TIDES diversity report
- Abortion rights (and 2024 election playbooks) face critical vote on Issue 1 in Ohio
- The end-call button on your iPhone could move soon. What to know about Apple’s iOS 17 change
- How to watch the 'Blue Bloods' Season 14 finale: Final episode premiere date, cast
- Colin Cowherd includes late Dwayne Haskins on list of QBs incapable of winning Super Bowls
- Air Force veteran Tony Grady joins Nevada’s crowded Senate GOP field, which includes former ally
- ‘Native American’ or ‘Indigenous’? Journalism group rethinks name
- Mets have visions of grandeur, and a dynasty, with Juan Soto as major catalyst
- New England hit with heavy rain and wind, bringing floods and even a tornado
Ranking
- Brianna LaPaglia Reveals The Meaning Behind Her "Chickenfry" Nickname
- NYC doctor sexually assaulted unconscious patients and filmed himself doing it, prosecutors say
- Tory Lanez expected to be sentenced for shooting Megan Thee Stallion: Live updates on Day 2
- Ohio State athletic director Gene Smith says he’ll retire in July 2024
- Paige Bueckers vs. Hannah Hidalgo highlights women's basketball games to watch
- BTS' Suga enlists for mandatory South Korea military service
- Sacramento mayor trades barbs with DA over 'unprecedented' homeless crisis
- Massachusetts governor declares state of emergency amid influx of migrants seeking shelter
Recommendation
Finally, good retirement news! Southwest pilots' plan is a bright spot, experts say
How a Gospel album featuring a drag queen topped Christian music charts
US Navy sailor’s mom encouraged him to pass military details to China, prosecutor says
This 8-year-old can't believe her eyes when her Navy brother surprises her at school
Israel lets Palestinians go back to northern Gaza for first time in over a year as cease
Barbie global ticket sales reach $1 billion in historic first for women directors
Abortion rights (and 2024 election playbooks) face critical vote on Issue 1 in Ohio
Jimmy Carter's Grandson Shares Health Update on Really Sick Former President