HackingTargetedEmployee Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENTMediumContained
NISSAN NORTH AMERICA, INC.
bd_a270e89ba8e11073 · schema v1 · pii pii-v1
Full breach record for NISSAN NORTH AMERICA, INC. →Nissan North America, Inc. disclosed a targeted cyberattack discovered on November 7, 2023. An unauthorized actor accessed employee personal information, including names, addresses, and potentially Social Security numbers. The incident affected employees in multiple states, including California. Nissan engaged cybersecurity experts, contained the threat, and is offering 24 months of identity monitoring services to affected employees.
California clockDiscovered Nov 7, 2023 → Notified May 15, 2024190d ✗ CA 60-day late27 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_019206705c1b1957Montana State AGfiled 2024-05-14Candidate
- bd_3b0533440a89abdaMaine State AGfiled 2024-05-14Verified
- bd_a59484e9435b26e2New Hampshire State AGfiled 2024-05-14Verified
- bd_a4b8e4f0871ced96Indiana State AGfiled 2024-05-15(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_f9f622a7f0322044Vermont State AGfiled 2024-05-15(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-585372
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2024
- Raw hash
- b1cb00a08499b4b3f85869effb436547a43628e345cc5f76f42472ca10c36e56
Reporting entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Victim entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Incident
- Discovered
- Nov 7, 2023
- Materiality determined
- —
- Notification sent
- May 15, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- CA 60-day late · 190d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 7, 2023→ Notified: May 15, 2024190d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.