Current:Home > NewsNissan data breach exposed Social Security numbers of thousands of employees -MoneyTrend
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-18 12:31:25
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (65348)
Related
- A White House order claims to end 'censorship.' What does that mean?
- US Rep. Annie Kuster of New Hampshire won’t seek reelection for a seventh term in November
- Georgia Power makes deal for more electrical generation, pledging downward rate pressure
- 'Truth vs. Alex Jones': Documentary seeks justice for outrageous claims of Sandy Hook hoax
- 'Squid Game' without subtitles? Duolingo, Netflix encourage fans to learn Korean
- Baltimore bridge collapse: Ships carrying cars and heavy equipment need to find a new harbor
- MLB predictions 2024: Who's winning it all? World Series, MVP, Cy Young picks
- Evers signs new laws designed to bolster safety of judges, combat human trafficking
- At site of suspected mass killings, Syrians recall horrors, hope for answers
- A $500K house was built on the wrong Hawaii lot. A legal fight is unfolding over the mix-up
Ranking
- NHL in ASL returns, delivering American Sign Language analysis for Deaf community at Winter Classic
- Steward Health Care strikes deal to sell its nationwide physician network to Optum
- Ex-Diddy associate alleges arrested Brendan Paul was mogul's drug 'mule,' Yung Miami was sex worker
- US Rep. Annie Kuster of New Hampshire won’t seek reelection for a seventh term in November
- Woman dies after Singapore family of 3 gets into accident in Taiwan
- 34 Container Store Items That Will Organize Your Kitchen
- 'Home Improvement' star Zachery Ty Bryan charged after arrest with felony DUI, hit and run
- A man has been arrested for randomly assaulting a young woman on a New York City street
Recommendation
Megan Fox's ex Brian Austin Green tells Machine Gun Kelly to 'grow up'
'Home Improvement' star Zachery Ty Bryan charged after arrest with felony DUI, hit and run
Kristen Stewart Shares She and Fiancée Dylan Meyer Have Frozen Their Eggs
Interior Department rule aims to crack down on methane leaks from oil, gas drilling on public lands
Travis Hunter, the 2
Subaru recalls 118,000 vehicles due to airbag issue: Here's which models are affected
USWNT's Midge Purce will miss Olympics, NWSL season with torn ACL: 'I'm heartbroken'
Trump Media, Reddit surge despite questionable profit prospects, taking on the ‘meme stock’ mantle