MalwareRansomwareRansom DemandedEmployee Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTHighContained
NISSAN NORTH AMERICA, INC.
bd_3b0533440a89abda · schema v1 · pii pii-v1
Full breach record for NISSAN NORTH AMERICA, INC. →On November 7, 2023, Nissan North America, Inc. (NNA) experienced a ransomware attack where a threat actor breached its external VPN, shut down systems, and demanded a ransom. The investigation confirmed on February 28, 2024, that personal information of 53,038 individuals, primarily current and former employees, was accessed. The compromised data included Social Security numbers. NNA began notifying affected individuals on May 15, 2024, and offered 24 months of identity theft protection services through Experian.
Maine clockDiscovered Feb 28, 2024 → Filed with AG May 14, 202476d ⏱ ME AG >30d11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_019206705c1b1957Montana State AGfiled 2024-05-14Candidate
- bd_a270e89ba8e11073California State AGfiled 2024-05-14Verified
- bd_a59484e9435b26e2New Hampshire State AGfiled 2024-05-14Verified
- bd_a4b8e4f0871ced96Indiana State AGfiled 2024-05-15(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_f9f622a7f0322044Vermont State AGfiled 2024-05-15(1d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d34f3290-0126-421f-9d69-5ccd31652641.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2024
- Raw hash
- 38aaf63f6bbc76bebf0135ab45876cf11449a4f337771d3ff43ce133c9e427d2
Reporting entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Victim entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Incident
- Discovered
- Feb 28, 2024
- Materiality determined
- —
- Notification sent
- May 15, 2024
- Affected individuals
- 53,038
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- ME AG >30d · 76dME resident >60d · 77d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 28, 2024→ Filed with AG: May 14, 202476d 30 days (soft) ME AG >30d Maine Discovered: Feb 28, 2024→ Notified: May 15, 202477d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.