2023 Nissan North America — VPN intrusion; extortion; >53k current/former employees (SSNs)
Data compromised
HR/employment identifiers and personal names per regulatory notification summaries
Technical writeup
Nissan North America told regulators that on November 7, 2023 it detected a targeted cyberattack where a threat actor abused its external VPN, copied material from local and network shares, and issued ransom demands without achieving wholesale encryption. Forensics initially emphasized business files, but late February 2024 review surfaced employee PII—primarily names and Social Security numbers—prompting Maine-style breach indexing and Experian identity-services offers. Coverage at the time contrasted this North American episode with parallel Oceania / Akira headlines targeting other Nissan divisions.
Root cause
External VPN leveraged for network intrusion and selective data theft (smash-and-grab extortion pattern)