Current:Home > reviewsNissan data breach exposed Social Security numbers of thousands of employees -FutureProof Finance
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-12 08:52:48
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (4)
Related
- Tarte Shape Tape Concealer Sells Once Every 4 Seconds: Get 50% Off Before It's Gone
- Biden and Trump: How the two classified documents investigations came to different endings
- Former Olympian set to plead guilty to multiple charges of molesting boys in 1970s
- CIA terminates whistleblower who prompted flood of sexual misconduct complaints
- Mets have visions of grandeur, and a dynasty, with Juan Soto as major catalyst
- Faced with wave of hostile bills, transgender rights leaders are playing “a defense game”
- Man charged with stealing small airplane that crashed on a California beach
- Does Nick Cannon See a Future With Mariah Carey After Bryan Tanaka Breakup? He Says...
- A South Texas lawmaker’s 15
- US wildlife service considering endangered status for tiny snail near Nevada lithium mine
Ranking
- Whoopi Goldberg is delightfully vile as Miss Hannigan in ‘Annie’ stage return
- Christian Bale breaks ground on foster homes he's fought for 16 years to see built
- Netanyahu rejects Hamas' Gaza cease-fire demands, says troops will push into Rafah
- Paul Giamatti says Cher 'really needs to talk to' him, doesn't know why: 'It's killing me'
- 'Vanderpump Rules' star DJ James Kennedy arrested on domestic violence charges
- Disney gets stock bump after talking Fortnite, Taylor Swift, Moana
- Millions could place legal bets on the Super Bowl. Just not in California or Missouri
- Everything You Need for that Coastal Cool Home Aesthetic We All Can’t Get Enough of
Recommendation
Trump's 'stop
The race for George Santos’ congressional seat could offer clues to how suburbs will vote this year
Man ticketed for shouting expletive at Buffalo officer can sue police, appeals court rules
Deadly military helicopter crash among many aviation disasters in Southern California
Sarah J. Maas books explained: How to read 'ACOTAR,' 'Throne of Glass' in order.
Polyamory has hit reality TV with 'Couple to Throuple.' Expect to challenge your misconceptions.
MLB spring training schedule 2024: First games, report dates for every team
Defense requests a mistrial in Jam Master Jay murder case; judge says no but blasts prosecutors