Current:Home > InvestNissan data breach exposed Social Security numbers of thousands of employees -AssetLink
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-19 20:36:24
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (89)
Related
- IRS recovers $4.7 billion in back taxes and braces for cuts with Trump and GOP in power
- Duke Energy seeks new ways to meet the Carolinas’ surging electric demand
- Colorado legal settlement would raise care and housing standards for trans women inmates
- Video shows bear cubs native to Alaska found wandering 3,614 miles away — in Florida
- The FTC says 'gamified' online job scams by WhatsApp and text on the rise. What to know.
- NCAA recorded nearly $1.3 billion in revenue in 2023, putting net assets at $565 million
- Mystery surrounds SUV that drove off Virginia Beach pier amid search for missing person
- Watch: Pipeline explosion shoots flames 500 feet high, reportedly seen in three states
- Civic engagement nonprofits say democracy needs support in between big elections. Do funders agree?
- FDA says 561 deaths tied to recalled Philips sleep apnea machines
Ranking
- Paris Olympics live updates: Quincy Hall wins 400m thriller; USA women's hoops in action
- Nikki Haley has called out prejudice but rejected systemic racism throughout her career
- Apple ends yearlong sales slump with slight revenue rise in holiday-season period but stock slips
- Punxsutawney Phil prepares to make his annual Groundhog Day winter weather forecast
- $73.5M beach replenishment project starts in January at Jersey Shore
- Why the FTC is cracking down on location data brokers
- Biden signs order approving sanctions for Israeli settlers who attacked Palestinians in the West Bank
- The Daily Money: Child tax credit to rise?
Recommendation
Olympic disqualification of gold medal hopeful exposes 'dark side' of women's wrestling
Britney Spears Fires Back at Justin Timberlake for Talking S--t at His Concert
Formula 1 star Lewis Hamilton to depart Mercedes for Ferrari in 2025
Apple ends yearlong sales slump with slight revenue rise in holiday-season period but stock slips
North Carolina justices rule for restaurants in COVID
Prosecutors detail possible expert witnesses in federal case against officers in Tyre Nichols death
Ranking all 57 Super Bowls from best to worst: How does first Chiefs-49ers clash rate?
FDA says 561 deaths tied to recalled Philips sleep apnea machines