Current:Home > reviewsNissan data breach exposed Social Security numbers of thousands of employees -USAMarket
Nissan data breach exposed Social Security numbers of thousands of employees
View
Date:2025-04-17 18:46:44
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (76535)
Related
- Senate begins final push to expand Social Security benefits for millions of people
- Miss America 2024 is active-duty Air Force officer, Harvard student: Meet Madison Marsh
- Inquest begins into a 2022 stabbing rampage in Canada that killed 11 and injured 17
- Emmys 2023: How Elvis Helped Prepare Riley Keough for Daisy Jones
- Person accused of accosting Rep. Nancy Mace at Capitol pleads not guilty to assault charge
- Guinness World Records suspends ‘oldest dog ever’ title for Portuguese canine during a review
- Tired of the Mess? The Best Easy-Organizing Products That'll Make a Huge Difference in Your Daily Routine
- Miss America 2024 is active-duty Air Force officer, Harvard student: Meet Madison Marsh
- Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Hi Hi!
- USC QB Caleb Williams declares for 2024 NFL draft; expected to be No. 1 pick
Ranking
- California DMV apologizes for license plate that some say mocks Oct. 7 attack on Israel
- Rob McElhenney Knows His Priorities While Streaming Eagles Game from the 2023 Emmys
- With ‘God’s-eye view,’ secretive surveillance flights keep close watch on Russia and Ukraine
- Flight school owner, student pilot among dead in Massachusetts small plane crash
- Arkansas State Police probe death of woman found after officer
- Jenna Ortega's 2023 Emmys Look Proves Her Wednesday-Inspired Style Is Over
- These Valentine’s Day Edits From Your Favorite Brands Will Make Your Heart Skip a Beat
- Janet Jackson is going back on tour: See where the superstar is performing this summer
Recommendation
Man can't find second winning lottery ticket, sues over $394 million jackpot, lawsuit says
How Margaret Mead's research into utopias helped usher in the psychedelic era
Lebanon’s top court suspends arrest warrant for former cabinet minister in Beirut port blast case
From Hot Priest to ‘All of Us Strangers,’ Andrew Scott is ready to ‘share more’ of himself
House passes bill to add 66 new federal judgeships, but prospects murky after Biden veto threat
Ex-President Donald Trump is set to face a jury over a columnist’s sex abuse and defamation claims
Provider of faulty computer system apologizes to hundreds affected by UK Post Office scandal
What's open and closed on Martin Luther King Jr. Day