Current:Home > ScamsNissan data breach exposed Social Security numbers of thousands of employees -Wealthify
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 06:59:41
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (33)
Related
- Senate begins final push to expand Social Security benefits for millions of people
- Senate committee advances bill to create a new commission to review Kentucky’s energy needs
- SEC approves rule that requires some companies to publicly report emissions and climate risks
- Luck strikes twice for Kentucky couple who lost, then found, winning lottery ticket
- Tree trimmer dead after getting caught in wood chipper at Florida town hall
- Police continue search for missing 3-year-old boy Elijah Vue in Wisconsin: Update
- What is the State of the Union? A look at some of the history surrounding the annual event
- Senate committee advances bill to create a new commission to review Kentucky’s energy needs
- 'Malcolm in the Middle’ to return with new episodes featuring Frankie Muniz
- You Only Have 66 Minutes To Get 66% off These 66 Gymshark Products- This Is Not a Drill
Ranking
- The White House is cracking down on overdraft fees
- Oscar Mayer hot dogs, sausages are latest foods as plant-based meat alternatives
- Colorado River States Have Two Different Plans for Managing Water. Here’s Why They Disagree
- Which streamer will target password sharing next? The former HBO Max looks ready to make its play
- Kylie Jenner Shows Off Sweet Notes From Nieces Dream Kardashian & Chicago West
- After Ohio train derailment, tank cars didn’t need to be blown open to release chemical, NTSB says
- Two men fought for jobs in a river-town mill. 50 years later, the nation is still divided.
- Black Keys, Dave Grohl, Tom Morello to perform at NY concert: How to watch online for $20
Recommendation
Newly elected West Virginia lawmaker arrested and accused of making terroristic threats
Caitlin Clark's potential WNBA contract might come as a surprise, and not a positive one
Texas wildfires: Map shows scope of devastation, learn how you can help those impacted
Did the moose have to die? Dog-sledding risk comes to light after musher's act of self-defense
Buckingham Palace staff under investigation for 'bar brawl'
Progressive Los Angeles County District Attorney George Gascón advances to runoff
European regulators want to question Apple after it blocks Epic Games app store
North Carolina schools chief loses primary to home-schooling parent critical of ‘radical agendas’