Current:Home > StocksNissan data breach exposed Social Security numbers of thousands of employees -WealthPro Academy
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-14 22:45:29
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (36)
Related
- The seven biggest college football quarterback competitions include Michigan, Ohio State
- Gun violence is the ultimate ‘superstorm,’ President Biden says as he announces new federal effort
- Jury convicts ex-NFL draft prospect of fatally shooting man at Mississippi casino
- Biden aims to remove medical bills from credit scores, making loans easier for millions
- Jury selection set for Monday for ex-politician accused of killing Las Vegas investigative reporter
- Who does a government shutdown affect most? Here's what happens to the agencies Americans rely on.
- Watch what happens after these seal pups get tangled in a net and are washed on shore
- EU hits Intel with $400 million antitrust fine in long-running computer chip case
- Family of explorer who died in the Titan sub implosion seeks $50M-plus in wrongful death lawsuit
- Gases from Philippine volcano sicken dozens of children, prompting school closures in nearby towns
Ranking
- Man can't find second winning lottery ticket, sues over $394 million jackpot, lawsuit says
- Why Chris Olsen Is Keeping His New Boyfriend’s Identity a Secret
- UAW's Fain announces expanded strike, targets 38 GM, Stellantis distribution plants
- A tale of two teams: Taliban send all-male team to Asian Games but Afghan women come from outside
- $1 Frostys: Wendy's celebrates end of summer with sweet deal
- UAW's Fain announces expanded strike, targets 38 GM, Stellantis distribution plants
- Coerced, censored, shut down: How will Supreme Court manage social media's toxic sludge?
- The UAW strike is growing. What you need to know as more auto workers join the union’s walkouts
Recommendation
USA women's basketball live updates at Olympics: Start time vs Nigeria, how to watch
Lorde gets emotional about pain in raw open letter to fans: 'I ache all the time'
The new iPhone 15, Plus, Pro and Pro Max release on Friday. Here's everything to know.
Biden aims to remove medical bills from credit scores, making loans easier for millions
Eva Mendes Shares Message of Gratitude to Olympics for Keeping Her and Ryan Gosling's Kids Private
This week on Sunday Morning (September 24)
Amazon Prime Video will start running commercials starting in early 2024
Capitol rioter who attacked AP photographer and police officers is sentenced to 5 years in prison