Current:Home > ContactNissan data breach exposed Social Security numbers of thousands of employees -Pinnacle Profit Strategies
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-14 15:01:13
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (24627)
Related
- SFO's new sensory room helps neurodivergent travelers fight flying jitters
- 'Heartstopper' bursts with young queer love, cartoon hearts and fireworks
- Judge rejects Trump's counterclaim against E. Jean Carroll
- Arrest warrants issued for Alabama riverfront brawl
- Arkansas State Police probe death of woman found after officer
- Leader of Texas’ largest county takes leave from job for treatment of clinical depression
- US investigating power-assisted steering failure complaints in older Ram pickup trucks
- Trump's attorneys argue for narrower protective order in 2020 election case
- Trump invites nearly all federal workers to quit now, get paid through September
- 'The Lincoln Lawyer' Season 2 ending unpacked: Is Lisa guilty? Who's buried by the cilantro?
Ranking
- Meta releases AI model to enhance Metaverse experience
- Appeals court upholds Josh Duggar’s conviction for downloading child sex abuse images
- Texas judge dismisses murder charge against babysitter who served 15 years over toddler’s death
- Australian police charge 19 men with child sex abuse after FBI tips about dark web sharing
- What do we know about the mysterious drones reported flying over New Jersey?
- Loch Ness Centre wants new generation of monster hunters for biggest search in 50 years
- DeSantis acknowledges Trump's defeat in 2020 election: Of course he lost
- 'A full-time job': Oregon mom's record-setting breastmilk production helps kids worldwide
Recommendation
Trump's 'stop
Kate Spade 24-Hour Flash Deal: Get This $300 Tote Bag for Just $69
Kim Kardashian Shares She Broke Her Shoulder
What to know about beech leaf disease, the 'heartbreaking' threat to forests along the East Coast
As Trump Enters Office, a Ripe Oil and Gas Target Appears: An Alabama National Forest
Ex-NYPD commissioner Bernard Kerik meets with special counsel investigators in 2020 election probe
3 killed by landslides at base camp of a Hindu temple in northern India; 17 others still missing
Usme leads Colombia to a 1-0 win over Jamaica and a spot in the Women’s World Cup quarterfinals