Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026

Major Increase in Ransomware Attacks Targeting Europe, Warns Report

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Nissan: Thousands Impacted By Red Hat Breach
News

Nissan: Thousands Impacted By Red Hat Breach

Team-CWDBy Team-CWDDecember 23, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


One of Japan’s leading carmakers has revealed a third-party data breach impacting 21,000 customers.

Nissan said that the breach stemmed from a compromise at Red Hat in September.

“Nissan Motor Co received a report from Red Hat, the company it had contracted to develop a customer management system for its dealerships, that the company’s data server had been accessed illegally and data had been leaked,” the statement explained.

“It was subsequently confirmed that the data leaked from the company included some customer information for Nissan Fukuoka Sales Co.”

Nissan said it received a notification from Red Hat on October 3 and immediately informed domestic regulator, the Personal Information Protection Commission. It is also in the process of contacting individual customers who have been affected.

The stolen information includes names, addresses, phone numbers, partial email addresses and “other customer-related information used for sales activities,” but not card details, the carmaker confirmed.

“At this time, there has been no confirmation that the leaked information has been used for secondary purposes. However, we ask that you be extremely cautious of any suspicious phone calls or mail you receive,” it added.

“Furthermore, the servers used by Red Hat do not store any customer information other than the data that was leaked this time, so there is no risk of further data leaks.”

Read more on Nissan data breaches: 53,000 Employees’ Social Security Numbers Exposed in Nissan Data Breach

Red Hat in the Crosshairs

An extortion group dubbed “Crimson Collective” claimed the attack on Red Hat’s private GitLab repositories, stealing nearly 570GB of data across 28,000 internal projects. This reportedly included around 800 Customer Engagement Reports (CERs) detailing customer networks and platforms. 

Targeting Red Hat’s consulting business, the threat actors found authentication tokens, full database URIs and other sensitive information in Red Hat code and CERs, which they used to access customer infrastructure. 

A list of the allegedly compromised CERs dating back to 2020 and posted by the group on Telegram included big-name brands such as Bank of America, T-Mobile, AT&T, Fidelity, Kaiser, Mayo Clinic, Walmart, Costco, the US Navy’s Naval Surface Warfare Center, Federal Aviation Administration and the House of Representatives.

This isn’t the first time Nissan has been caught up in a data breach incident. A ransomware attack in late 2023 led to the compromise of personal information impacting over 53,000 of its North America employees.

That same year, Nissan North America was forced to notify around 18,000 customers that their data may have been inadvertently exposed by a third-party supplier.

Image credit: Wongsakorn 2468 / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePhantom Stealer Spread by ISO Phishing Emails Hitting Russian Finance Sector
Next Article A Browser Extension Risk Guide After the ShadyPanda Campaign
Team-CWD
  • Website

Related Posts

News

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
News

Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

June 26, 2026
News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Is it time for internet services to adopt identity verification?

January 14, 2026

The quest for greater tech independence

May 19, 2026

How to tell if a voice call is AI or not

February 23, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.