Nissan North America breach exposed Social Security numbers of 53,000 employees

Organization
Nissan North America
Exploit
Ransomware
Industry
Automotive

Nissan North America notified more than 53,000 current and former employees in May 2024 that their names and Social Security numbers had been taken in a ransomware attack. A filing with the Office of the Maine Attorney General dated 15 May 2024 put the figure at 53,038 people.

Nissan learned on 7 November 2023 that it was the victim of a targeted cyberattack against its external VPN, in which the attacker shut down some systems and demanded a ransom payment. Nissan's initial review suggested only business information had been touched, and the company briefed staff on the incident at a town hall meeting in December 2023. Further forensic work completed on 28 February 2024 established that employee personal data had also been copied.

Nissan said no financial information was involved and that it had seen no evidence of fraud or identity theft linked to the incident. The company notified law enforcement, brought in outside cybersecurity specialists, reset passwords across the enterprise, deployed additional endpoint monitoring and ran vulnerability scans.

Affected employees were offered two years of complimentary credit monitoring and identity theft protection. No ransomware group publicly claimed the attack, and Nissan did not disclose whether it paid. SecurityWeek noted that a separate 2023 attack on Nissan Oceania was claimed by the Akira ransomware group, and that it is unclear whether the two incidents are related.

Sources