Nissan warns Australian and New Zealand customers after Akira ransomware breach

Organization
Nissan Oceania
Exploit
Ransomware
Industry
Automotive

Nissan disclosed on December 5, 2023 that its systems in Australia and New Zealand had been breached. The carmaker posted a notice on its regional website warning customers that their personal information might have been accessed and urging them to watch for scams and phishing attempts.

Nissan gave no detail at the time about what had been taken, saying only that it was working with security specialists to determine the scope of the incident, that it was restoring affected systems, and that it had notified the relevant authorities in both countries. Roughly two weeks later the Akira ransomware group claimed responsibility, saying it had taken about 100 gigabytes of files including employee records, non-disclosure agreements, project material and information on partners and clients. Akira went on to publish files it said came from Nissan, indicating that no ransom had been paid.

Nissan completed its review in March 2024 and said around 100,000 people in Australia and New Zealand would be notified, a figure it expected to fall once duplicate and unreachable records were removed. About 10 percent of those had government identification exposed, including roughly 7,500 driver's licences, 4,000 Medicare cards, 1,300 tax file numbers and 220 passports. The remaining 90 percent had other personal details exposed, such as dates of birth, employment records or loan statements.

The company offered those affected free identity protection and credit monitoring and said it would reimburse the cost of replacing compromised government identity documents.

Sources