Nissan has confirmed that the personal data of thousands of its customers was exposed following a cybersecurity incident that hit US software company Red Hat in September. While the breach did not directly affect Nissan's systems, its impact spread across the Japanese automaker through a partnered digital infrastructure.

Indirect blow to a global automotive giant
Headquartered in Yokohama, Nissan is one of the world's largest automobile manufacturers, with annual production exceeding 3.2 million vehicles. The company employs approximately 120,000 people and maintains a strong presence in markets such as Japan, North America, Europe and Asia.
See also: DDoS attack targeted France's National Postal Service
In an official statement, Nissan announced that it was affected by a security breach that occurred in a Red Hat environment, which was used for support operations.
What data was leaked – What was not affected
According to the company, the data exposed includes:
- Customer names
- Physical addresses
- Phone numbers
- Email addresses
- Customer information related to sales and commercial transactions
Specifically, approximately 21,000 customers who purchased vehicles or received services at Nissan in Fukuoka, Japan, were affected by the breach.
Nissan clarified that no financial or banking information, such as credit card numbers or payment data, was leaked, which limits the immediate financial risk to affected users.
See also: University of Phoenix: Data breach affects 3.5 million people

The attack on Red Hat and the role of hackers
The Red Hat breach, which was revealed in early October and involved the theft of hundreds of gigabytes of data from around 28,000 private GitLab repositories, was initially claimed by the Crimson Collective, known for large-scale attacks on corporate software development environments.
Later, the infamous ShinyHunters group was also involved in the incident , hosting samples of the stolen data on its extortion platform, increasing the pressure on Red Hat and its partners.
Nissan's stance and initial reactions
Nissan said the Red Hat environment did not store any more data than has already been confirmed as affected, and stressed that there is no indication so far that the leaked information has been used maliciously.
A worrying pattern of cyberattacks
This incident is the second cybersecurity incident for Nissan Japan in 2025, following a ransomware attack by the Qilin in late August, which hit subsidiary Creative Box Inc. (CBI).
See also: University of Sydney: Student and staff data breach

At the same time, in 2024 Nissan North America suffered a data breach involving 53,000 employees, while Nissan Oceania announced that a ransomware attack by the Akira group exposed the personal information of approximately 100,000 customers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Bigger Picture: Third-Party Providers and Digital Risk
The case highlights the growing risk posed by large organizations’ reliance on third-party technology providers. Even when internal systems remain secure, a security breach in a collaborative platform can have serious consequences for reputation and customer trust.
In an era where the automotive industry increasingly relies on software, cloud services and digital ecosystems, cybersecurity is emerging as a critical factor in operational sustainability.
Source: www.bleepingcomputer.com
