Current:Home > InvestNissan data breach exposed Social Security numbers of thousands of employees -Wealth Evolution Experts
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 20:31:20
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (85265)
Related
- A steeplechase record at the 2024 Paris Olympics. Then a proposal. (He said yes.)
- Norman Jewison, director and Academy Award lifetime achievement honoree, dead at 97
- Illinois shootings leave 8 people killed; suspect dead of self-inflicted gunshot in Texas, police say
- Kim Kardashian's SKIMS Valentine's Day Shop Features Lana Del Rey and Over 15 New Collections
- Oklahoma parole board recommends governor spare the life of man on death row
- US strikes three facilities in Iraq following attacks on American forces by Iran-backed militias
- UN chief warns that Israel’s rejection of a two-state solution threatens global peace
- What the health care sector is selling to Wall Street: The first trillion-dollar drug company is out there
- A Georgia governor’s latest work after politics: a children’s book on his cats ‘Veto’ and ‘Bill’
- Hollywood attorney Kevin Morris defends $5 million in loans to Hunter Biden
Ranking
- A South Texas lawmaker’s 15
- The Best Rotating Curling Irons of 2024 That Are Fool-Proof and Easy to Use
- Oscar nominations 2024: Justine Triet becomes 8th woman ever nominated for best director
- U.S. identifies Navy SEALs lost during maritime raid on ship with Iranian weapons
- Realtor group picks top 10 housing hot spots for 2025: Did your city make the list?
- The European Commission launches an in-depth look at competitive costs of the Lufthansa deal for ITA
- George Santos says he doesn’t plan to vote in the special election to fill his former seat
- Military veteran charged in Capitol riot is ordered released from custody
Recommendation
Federal court filings allege official committed perjury in lawsuit tied to Louisiana grain terminal
These Gym Bags Are So Stylish, You’ll Hit the Gym Just to Flaunt Them
Dwayne Johnson named to UFC/WWE group's board, gets full trademark rights to 'The Rock'
Michigan woman sentenced to life in prison in starvation death of son
What were Tom Selleck's juicy final 'Blue Bloods' words in Reagan family
Illinois based tech company's CEO falls to death in front of staff members at work party: Reports
NFL Reporter Doug Kyed Shares Death of 2-Year-Old Daughter After Leukemia Battle
Remains of Green River Killer's 49th and last known victim identified as teen Tammie Liles — but other cases still unsolved