Current:Home > MyNissan data breach exposed Social Security numbers of thousands of employees -Infinite Edge Capital
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-14 20:17:23
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (13444)
Related
- Nearly half of US teens are online ‘constantly,’ Pew report finds
- Pearl Jam throws a listening party for their new album that Eddie Vedder calls ‘our best work’
- North Carolina redistricting lawsuit tries `fair` election claim to overturn GOP lines
- Step Inside Jason Kelce and Kylie Kelce’s Winning Family Home With Their 3 Daughters
- What to know about Tuesday’s US House primaries to replace Matt Gaetz and Mike Waltz
- Man who killed 2 women near the Las Vegas Strip is sentenced to life in prison
- Stock market today: Wall Street drops to worst loss in months with Big Tech, hope for March rate cut
- 75-year-old man dies after sheriff’s deputy shocks him with Taser in rural Minnesota
- Selena Gomez engaged to Benny Blanco after 1 year together: 'Forever begins now'
- West Virginia construction firm to buy bankrupt college campus
Ranking
- Juan Soto to be introduced by Mets at Citi Field after striking record $765 million, 15
- Barcelona edges Osasuna in 1st game since coach Xavi announced decision to leave. Atletico also wins
- 75-year-old man dies after sheriff’s deputy shocks him with Taser in rural Minnesota
- Meta CEO Mark Zuckerberg apologizes to parents of victims of online exploitation in heated Senate hearing
- Could Bill Belichick, Robert Kraft reunite? Maybe in Pro Football Hall of Fame's 2026 class
- Starbucks adds romance to the menu: See the 2 new drinks available for Valentine's Day
- 3 dead, 9 injured after 'catastrophic' building collapse near Boise, Idaho, airport
- Noah Kahan opens up about his surreal Grammy Awards nomination and path to success
Recommendation
See you latte: Starbucks plans to cut 30% of its menu
Pig café in Japan drawing dozens of curious diners who want to snuggle with swine
A Tennessee lawmaker helped pass a strict abortion law. He's now trying to loosen it
A Dallas pastor is stepping into Jesse Jackson’s role as leader of his Rainbow PUSH Coalition
Are Instagram, Facebook and WhatsApp down? Meta says most issues resolved after outages
Amelia Earhart's plane may have been found. Why are we obsessed with unsolved mysteries?
Russell Brand denies 'very hurtful' assault allegations in Tucker Carlson interview
UK judge dismisses Trump’s lawsuit over dossier containing ‘shocking and scandalous claims’