Serious questions about cybersecurity in the automotive industry are being raised by allegations by the hacking group Everest about a widespread breach of the systems of Nissan Motor Co., Ltd. Although the case is still under investigation, the scale of the alleged leak raises concerns about the protection of critical industrial and corporate data.

900 GB of data at the center of the allegations
According to initial reports circulating on underground cybercrime forums, the Everest group claims to have stolen around 900GB of sensitive data from Nissan. Such a volume of data suggests, if confirmed, extensive access to internal systems, corporate records and possibly infrastructure critical to the company’s operations.
Although the exact contents of the files have not been revealed, it is speculated that they may include internal documents, technical engineering files, supplier-related information, or even customer data.
See also: University of Hawaii: Hackers obtained Cancer Center patient data
Leakage as a pressure tool
The first signs of the alleged breach emerged through posts by the group on closed hacking forums, where sample files were published as “proof” of the breach. This practice is a common tactic in double-ransomware attacks, in which attackers not only encrypt databut also threaten to publicly leak it if a ransom is not paid.
The aim of such actions is to increase pressure on the victim, especially when it comes to multinational organizations with strict regulatory obligations and high business risk.

What do the first analyses show?
The case reported by analysts at Hackmanac, who issued a warning of a possible cyberattack targeting Nissan's manufacturing operations in Japan. They note that the incident remains under investigation, but the activity patterns align with known tactics of ransomware and data extortion groups.
See also: Instagram data leak: Platform says there was no breach
Attacks of this type are usually launched through exposed services, stolen VPN credentials, or well-designed phishing campaigns, targeting employees with access to critical systems.
From initial access to data extraction
Once they gain access, threat actors move laterally within the corporate network, mapping infrastructure and identifying high-value systems. Common targets include file servers, source code repositories, document management systems, and backup infrastructure.
In a next stage, attackers automate file collection, filtering data based on size and content to maximize the value of the leak. This data is typically compressed and extracted in stages, often in a manner that mimics normal outgoing traffic to avoid detection.
Why car manufacturers are an attractive target
Modern automakers are not just vehicle manufacturers, but technology giants with complex digital supply chains. They manage huge volumes of data related to research and development, autonomous systems, vehicle software and international supplier networks.
See also: Russian APT28 conducts credential theft campaign
A successful cyberattack on such an organization can have consequences that extend far beyond the company itself, affecting partners, factories, and markets worldwide.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Waiting for official placements
There has been no official confirmation from Nissan on the validity of the claims so far. However, the incident is a reminder that large-scale attacks remain a constant threat and that strengthening cybersecurity is now a strategic priority for heavy industry.
The Nissan case is expected to be of great concern to the cybersecurity community in the coming days, as new technical evidence gradually comes to light.
