惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
博客园 - Franky
大猫的无限游戏
大猫的无限游戏
博客园 - 三生石上(FineUI控件)
量子位
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
V
Visual Studio Blog
雷峰网
雷峰网
T
Tailwind CSS Blog
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
有赞技术团队
有赞技术团队
博客园 - 叶小钗
Microsoft Azure Blog
Microsoft Azure Blog
T
The Blog of Author Tim Ferriss
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
阮一峰的网络日志
阮一峰的网络日志
Y
Y Combinator Blog

Consumer Insights

Weverse data breach affects 422,584 user accounts Manchester Airports Group cyberattack exposes data of 8.7 million customers Sakura Internet hack may affect 1.36 million accounts French tax authority breach exposes data of 678,000 people and businesses Phone number leaked in the Bloctel breach? Here’s what to do. SplitVPN breach reveals 58 million hidden connection logs South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data
21,000 Nissan Customers Exposed After Third-Party Server ...
Vlad CONSTANTINESCU · 2025-12-24 · via Consumer Insights

Unauthorized access to a contractor-managed system led to the exposure of contact data for thousands of customers.

Red Hat-managed infrastructure breached

Nissan has disclosed a data breach affecting roughly 21,000 customers linked to a former dealership in Japan, following unauthorized access to a server managed by Red Hat. The intrusion was detected in late September, and Nissan was notified in early October, according to a breach notice published by the automaker in December.

The compromised environment was part of a Red Hat Consulting-managed GitLab instance. While Nissan gave few details of the attack, Red Hat has acknowledged that an intruder accessed and copied data from this system, confirming the incident involved customer-related information of multiple organizations.

The scope of the breach

Nissan said no payment card details were stolen. However, exposed data still comprises sensitive customer information, including:

  • Names
  • Addresses
  • Phone numbers
  • Partial email addresses
  • Other personal details used in sales and service operations

While the company says it has no evidence the data has been misused, the nature of the information raises concerns.

Such data is particularly valuable for social engineering, enabling threat actors to craft convincing emails, scam phone calls or fraudulent messages that appear to originate from legitimate businesses. Nissan has advised affected customers to remain vigilant for suspicious communications.

Attackers remain unnamed

Neither Nissan nor Red Hat has publicly attributed the breach to a specific threat actor. However, around the time the intrusion was detected, a group calling itself Crimson Collective claimed responsibility for breaching Red Hat’s private GitLab repositories, stealing hundreds of gigabytes of data in the process.

Red Hat later confirmed the breach and the group reportedly partnered with another cybercrime gang to pursue extortion. It remains unclear whether Nissan was directly targeted or caught up as part of a broader compromise of third-party infrastructure.

The recurring nature of breaches and what you can do about it

This incident marks Nissan’s third major data breach in three years, following earlier disclosures affecting employees in North America and customers in Oceania. The repeated incidents highlight the growing risks associated with supply-chain and third-party service providers.

For individuals impacted by data breaches, tools like Bitdefender Digital Identity Protection can help mitigate downstream risks. The service continuously monitors the public and dark web for exposed personal information, notifies users when their data appears in breaches and provides quick, one-click action items to patch weak spots in digital footprints.