Current:Home > MarketsNissan data breach exposed Social Security numbers of thousands of employees -TradeBridge
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 13:23:51
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (737)
Related
- Juan Soto to be introduced by Mets at Citi Field after striking record $765 million, 15
- Warren Buffett Faces Pressure to Invest for the Climate, Not Just for Profit
- Harry Potter's Miriam Margolyes Hospitalized With Chest Infection
- Carrying out executions took a secret toll on workers — then changed their politics
- A Mississippi company is sentenced for mislabeling cheap seafood as premium local fish
- Get a $49 Deal on $110 Worth of Tarte Makeup That Blurs the Appearance of Pores and Fine Lines
- Get That “No Makeup Makeup Look and Save 50% On It Cosmetics Powder Foundation
- Margot Robbie and Husband Tom Ackerley Step Out for Rare Date Night at Chanel Cruise Show
- A Mississippi company is sentenced for mislabeling cheap seafood as premium local fish
- This is America's most common text-messaging scam, FTC says
Ranking
- Meta releases AI model to enhance Metaverse experience
- Los Angeles county DA's office quits Twitter due to vicious homophobic attacks not removed by social media platform
- Mindy Kaling Reveals Her Exercise Routine Consists Of a Weekly 20-Mile Walk or Hike
- Environmental Group Alleges Scientific Fraud in Disputed Methane Studies
- Federal hiring is about to get the Trump treatment
- Feds Pour Millions into Innovative Energy Storage Projects in New York
- Her miscarriage left her bleeding profusely. An Ohio ER sent her home to wait
- FDA gives safety nod to 'no kill' meat, bringing it closer to sale in the U.S.
Recommendation
New data highlights 'achievement gap' for students in the US
Why Andy Cohen Was Very Surprised by Kim Zolciak and Kroy Biermann's Divorce
Mindy Kaling Reveals Her Exercise Routine Consists Of a Weekly 20-Mile Walk or Hike
Joran van der Sloot, prime suspect in Natalee Holloway's 2005 disappearance, pleads not guilty to extortion charges
Macy's says employee who allegedly hid $150 million in expenses had no major 'impact'
Regulators Pin Uncontrolled Oil Sands Leaks on Company’s Extraction Methods, Geohazards
Only Kim Kardashian Could Make Wearing a Graphic Tee and Mom Jeans Look Glam
A crash course in organ transplants helps Ukraine's cash-strapped healthcare system