HackingVulnerability ExploitStolen CredentialsTargetedData ExfiltratedEmployee Data InvolvedPIIIDENTITY_BASICLowContained
NISSAN NORTH AMERICA, INC.
bd_a59484e9435b26e2 · schema v1 · pii pii-v1
Full breach record for NISSAN NORTH AMERICA, INC. →Nissan North America, Inc. reported a targeted cyberattack on its external VPN discovered on November 7, 2023. The attacker demanded a ransom but did not encrypt data. The incident affected employee personal information, including 22 New Hampshire residents. Nissan contained the threat, notified law enforcement, reset passwords, implemented Carbon Black monitoring, and offered credit monitoring services.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_019206705c1b1957Montana State AGfiled 2024-05-14Candidate
- bd_3b0533440a89abdaMaine State AGfiled 2024-05-14Verified
- bd_a270e89ba8e11073California State AGfiled 2024-05-14Verified
- bd_a4b8e4f0871ced96Indiana State AGfiled 2024-05-15(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 1d gap
- bd_f9f622a7f0322044Vermont State AGfiled 2024-05-15(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/nissan-north-america-20240514.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 14, 2024
- Raw hash
- e814601d62887c274cc62b5da2dad9d4b3a81a75b86b8d2a4885abaed190f250
Reporting entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Victim entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Incident
- Discovered
- Nov 7, 2023
- Materiality determined
- —
- Notification sent
- May 15, 2024
- Affected individuals
- 22
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney GeneralNotified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.