Current:Home > NewsNissan data breach exposed Social Security numbers of thousands of employees -ValueCore
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-11 16:09:25
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (1)
Related
- Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Triathlon
- Kate Gosselin zip-tied son Collin and locked him in a basement, he claims
- US filings for unemployment benefits inch up slightly but remain historically low
- Oklahoma State coach Mike Gundy delivers truth bomb about reality of paying players
- Which apps offer encrypted messaging? How to switch and what to know after feds’ warning
- Why Olivia Rodrigo Skipped the 2024 MTV VMAs
- 2024 MTV VMAs: Katy Perry Makes Coy Reference to Orlando Bloom Sex Life While Accepting Vanguard Award
- Fearless Fund drops grant program for Black women business owners in lawsuit settlement
- Backstage at New York's Jingle Ball with Jimmy Fallon, 'Queer Eye' and Meghan Trainor
- The Daily Money: Trump vs Harris on the economy
Ranking
- Trump suggestion that Egypt, Jordan absorb Palestinians from Gaza draws rejections, confusion
- Patrick Mahomes brushes off comments made about his wife, Brittany, by Donald Trump
- Francine slams Southeast; most of New Orleans without power: Live updates
- Rangers prospect Kumar Rocker to make history as first MLB player of Indian descent
- Person accused of accosting Rep. Nancy Mace at Capitol pleads not guilty to assault charge
- The Dave Grohl new baby drama is especially disappointing. Here's why.
- Damar Hamlin timeline: How Bills safety recovered from cardiac arrest, became starter
- 2024 MTV VMAs: Taylor Swift Makes History With Artist of the Year Win
Recommendation
The Daily Money: Spending more on holiday travel?
Solheim Cup 2024: Everything to know about USA vs. Europe golf tournament
Earthquake rattles the Los Angeles area
Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Body Composition
Why we love Bear Pond Books, a ski town bookstore with a French bulldog 'Staff Pup'
Judge orders Tyrese into custody over $73K in child support: 'Getting arrested wasn't fun'
How Taylor Swift and Travis Kelce Reacted to Jason Kelce Discussing His “T-ts” on TV
Week 3 college football predictions: Expert picks for every Top 25 game