Current:Home > MarketsNissan data breach exposed Social Security numbers of thousands of employees-LoTradeCoin
Nissan data breach exposed Social Security numbers of thousands of employees
View Date:2025-01-11 09:36:28
Nissan suffered a data breach last November in a ransomware attack that exposed the Social Security numbers of thousands of former and current employees, the Japanese automaker said Wednesday.
Nissan's U.S.-based subsidiary, Nissan North America, detailed the cyberattack in a May 15 letter to affected individuals. In the letter, Nissan North America said a bad actor attacked a company virtual private network and demanded payment. Nissan did not indicate whether it paid the ransom.
"[U]pon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain and successfully terminate the threat," the car maker said in the letter, adding that "Nissan worked very closely with external cybersecurity professionals experienced in handling these types of complex security incidents."
Nissan told employees about the incident during a town hall meeting in December 2023, a month after the attack. The company also told staffers that it was launching an investigation and would notify employees privately if their personal information had been compromised. Nissan said it's providing free identity theft protection services to impacted individuals for two years.
Nissan North America also notified state officials across the U.S. of the attack, noting that data belonging to more than 53,000 current and former workers was compromised. But the company said its investigation found that affected individuals did not have their financial information exposed.
Nissan North America "has no indication that any information has been misused or was the attack's intended target," the automaker said in its letter.
Ransomware attacks, in which cybercriminals disable a target's computer systems or steal data and then demand payment to restore service, have become increasingly common. One cybersecurity expert said someone likely got a password or multi-factor authentication code from an existing Nissan employee, enabling the hacker to enter through the company's VPN.
"It is unfortunate that the breach ended up involving personal information, however Nissan has done the right thing by continuing to investigate the incident and reporting the update," Erich Kron, a cybersecurity awareness advocate at KnowBe4, told CBS MoneyWatch in an emailed statement. "In this case, targeting the VPN will often help bad actors avoid detection and bypass many of the organizational security controls that are in place."
- In:
- Nissan
- Data Breach
- Cyberattack
- Ransomware
Khristopher J. Brooks is a reporter for CBS MoneyWatch. He previously worked as a reporter for the Omaha World-Herald, Newsday and the Florida Times-Union. His reporting primarily focuses on the U.S. housing market, the business of sports and bankruptcy.
TwitterveryGood! (26948)
Related
- Police identify 7-year-old child killed in North Carolina weekend shooting
- The 2024 Tesla Model 3 isn't perfect, but fixes nearly everything we used to hate
- AP Top 25 Takeaways: Alabama is a national title contender again; Michigan may have its next man
- How many post-credit scenes and cameos in 'The Marvels'? All the best movie spoilers here
- Amazon Black Friday 2024 sales event will start Nov. 21: See some of the deals
- Barbie Secrets Revealed: All the Fantastic Behind-the-Scenes Bombshells
- Donald Trump Jr. returning to stand as defense looks to undercut New York civil fraud claims
- Long walk to school: 30 years into freedom, many kids in South Africa still walk miles to class
- Prosecutors say some erroneous evidence was given jurors at ex-Sen. Bob Menendez’s bribery trial
- A flight expert's hot take on holiday travel: 'Don't do it'
Ranking
- New York nursing home operator accused of neglect settles with state for $45M
- 3 dead, more than a dozen others injured in large Brooklyn house fire, officials say
- Constitutional challenge to Georgia voting machines set for trial early next year
- US conducts airstrikes against Iran-backed groups in Syria, retaliating for attacks on US troops
- Taking stock of bonds: Does the 60/40 rule still have a role in retirement savings?
- Police arrest Los Angeles man in connection with dismembered body, missing wife and in-laws
- US and South Korea sharpen deterrence plans over North Korean nuclear threat
- Lost in space: astronauts drop tool bag into orbit that you can see with binoculars
Recommendation
-
NATO’s Rutte calls for more Western support for Ukraine, warns of Russian alliances
-
Draymond Green curiously ejected after squabble with Cavaliers' Donovan Mitchell
-
Fathers away from home fear for family members stuck in Gaza as war rages: I am sick with worry
-
Louisville, Oregon State crash top 10 of US LBM Coaches Poll after long droughts
-
'Underbanked' households more likely to own crypto, FDIC report says
-
After barren shelves and eye-watering price mark-ups, is the Sriracha shortage over?
-
Olympic sports bodies want talks with IOC on threats from adding cricket and others to 2028 program
-
Jaguars embarrassed and humbled in a 34-3 loss to 49ers that ended a 5-game winning streak