HomeSecurityNissan North America: Data breach affects 53,000 employees

Nissan North America: Data breach affects 53,000 employees

Nissan North America (Nissan) suffered a data breach last year after a cybercriminal targeted the company's external VPN and shut down its systems

Nissan North America Data breach

The automaker discovered the breach in early November 2023 but has now issued a new statement, in which it says the personal data of more than 53,000 current and former employees was exposed.

As reported on December 5, 2023, Nissan learned that it was the victim of a targeted cyberattack on November 7, 2023. Upon learning of the attack, Nissan immediately notified law enforcement and began taking immediate action to investigate, contain, and successfully terminate the threat,” said in a notice sent to affected individuals.

See also: Santander: Customer and employee data breach

Nissan North America revealed that the attacker targeted external VPN and then shut down some of the company's systems. It then demanded a ransom. However, the company noted that none of its systems were encrypted during the attack.

In collaboration with external experts, the company was able to assess the situation and terminate the threat.

Subsequent investigation showed that the attacker had access to certain files on local and network shares, which mainly contained business information.

However, in late February, the company discovered that some personal information , mainly concerning current and former employees of the company, including Social Security numbers, had also been exposed.

Nissan North America sent a data breach notification to the Maine Attorney General's Office. It states that the exposed data included a personal identifier (e.g. name) and Social Security numbers. The breached records did not contain financial information.

See also: Singing River Health System: Data breach affects 895,000 people

There is currently no evidence that the breached data has been misused. However, to mitigate the risk of this data exposure, Nissan has provided some instructions to letter recipients on how to sign up for a free 24-month credit monitoring and identity (through Experian).

Nissan has been the target of several cyberattacks in recent years. In early December 2023, Nissan Oceania (Australia and New Zealand) announced an investigation into a cyberattack and possible data breach. In March 2024, the company confirmed that Akira ransomware had stolen data belonging to 100,000 of its customers.

Nissan North America: Data breach affects 53,000 employees

In January 2023, Nissan North America suffered an indirect breach, following a third-party vendor hack. The breach impacted thousands of customers once again. Two years earlier, the same subsidiary left a Git server repository exposed online , with default credentials. As a result, source code for internal applications and tools was exposed.

The Nissan North America data breach serves as a reminder of the growing threat of cyberattacks and the importance of implementing strong security measures. With increasing reliance on digital systems, companies must remain vigilant in protecting their sensitive data.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Companies should take steps to protocols cybersecurity and mitigate future risks. This includes collaborating with external experts, conducting regular security audits, and providing employees with resources to improve cyber hygiene.

See also: Helsinki: Data breach affects thousands of people

In addition, it is important to train employees in identifying and responding to threats and to implement basic security, such as using strong and unique passwords, implementing multi-factor authentication, and avoiding opening suspicious emails and attachments.

As technology continues to advance and cyber threats become more sophisticated, it is important for companies like Nissan to continually review and update their security measures. By prioritizing cybersecurity, companies can protect not only their own data but also the personal information of their employees and customers.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS