Current:Home > ContactNissan data breach exposed Social Security numbers of thousands of employees -TradeGrid
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-14 19:50:50
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (546)
Related
- What do we know about the mysterious drones reported flying over New Jersey?
- Melinda French Gates to resign from Gates Foundation: 'Not a decision I came to lightly'
- 'Taylor Swift baby' goes viral at concert. Are kids allowed – and should you bring them?
- To the moms all alone on Mother's Day, I see you and you are enough.
- Travis Hunter, the 2
- North Carolina congressional runoff highlights Trump’s influence in GOP politics
- Psst! Everything at J. Crew Factory Is up to 60% off Right Now, Including Cute Summer Staples & More
- Assistant school principal among 4 arrested in cold case triple murder mystery in Georgia
- Angelina Jolie nearly fainted making Maria Callas movie: 'My body wasn’t strong enough'
- Alabama follows DeSantis' lead in banning lab-grown meat
Ranking
- IRS recovers $4.7 billion in back taxes and braces for cuts with Trump and GOP in power
- 2024 Preakness Stakes post position draw: Where Derby winner Mystik Dan, others will start
- Iowa women's basketball coach Lisa Bluder announces retirement after 24 seasons
- Return of the meme stock? GameStop soars after 'Roaring Kitty' resurfaces with X post
- Selena Gomez engaged to Benny Blanco after 1 year together: 'Forever begins now'
- Roku Channel to carry MLB games each Sunday as part of 'Sunday Leadoff'
- Red Sox great David Ortiz, who frustrated Yankees, honored by New York Senate
- Pro-union ad featuring former Alabama coach Nick Saban was done without permission, he says
Recommendation
Pressure on a veteran and senator shows what’s next for those who oppose Trump
Melinda French Gates to resign from Gates Foundation: 'Not a decision I came to lightly'
How a group of veterans helped a U.S. service member's mother get out of war-torn Gaza
Travis Barker’s Extravagant Mother’s Day Gift to Kourtney Kardashian Is No Small Thing
Retirement planning: 3 crucial moves everyone should make before 2025
Proposed Minnesota Equal Rights Amendment draws rival crowds to Capitol for crucial votes
Howard University cancels nurses' graduation mid-ceremony after door is smashed
Truck driver accused of intentionally killing Utah officer had been holding a woman against her will