News: 1710376333

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

(2024/03/14)


Over the next few weeks, Nissan Oceania will make contact with around 100,000 people in Australia and New Zealand whose data was pilfered in a December 2023 attack on its systems – perhaps by the Akira ransomware gang.

The cyberbaddies stole some form of government identification from up to ten percent of victims. Among the data stolen from the automotive manufacturer was info on 4,000 Medicare cards - Australia's national health insurance scheme - plus 7,500 driving licenses, 220 passports, and 1,300 tax file numbers.

The remaining 90 percent of folks had other info stolen - perhaps copies of loan-related transaction statements, employment details, or salary information. The heist may also include personally identifiable information (PII) such as dates of birth.

[1]

Some of those affected by the breach were customers of finance services that Nissan operated and branded for rival automakers Mitsubishi, Renault, Infiniti, LDV, and RAM.

[2]

[3]

"We know this will be difficult news for people to receive, and we sincerely apologize to our community for any concerns or distress it may cause," Nissan [4]said in a statement posted to its website.

"We are committed to contacting affected individuals as soon as possible to tell them what information was involved, how we are supporting them, and the steps they can take to protect themselves against the risk of harm, identity theft, scams, or fraud."

[5]

In Australia, affected individuals are being offered 12 months of free credit monitoring from Equifax, and in New Zealand, a similar service is being made available through Centrix.

Individuals in both territories will also have access to IDCARE's services for protecting against the misuse of stolen data, and those who need ID documents replaced can claim the cost back with Nissan Oceania.

Ransomware at play?

The company didn't say at the time whether ransomware was involved, and still hasn't mentioned it today, but the original intrusion was claimed by [6]the Akira group .

[7]Stanford University failed to detect ransomware intruders for 4 months

[8]UK council yanks IT systems and phone lines offline following cyber ambush

[9]Car industry pleads for delay to post-Brexit tariffs on EVs

[10]US launches official probe into Cruise after pair of pedestrian accidents

Data supposedly belonging to Nissan Oceania is available to download via Akira's website, suggesting that if ransomware was involved the automaker refused to pay.

Akira claims to have stolen 100 GB worth of data, including personal data. "They seem to not be very interested in the data, so you can find their stuff here," Akira's website reads.

"You will find docs with personal information of their employees in the archives and much other interested stuff like NDAs, projects, information about clients and partners etc."

[11]

Akira has been responsible for attacks on many other major organizations since spinning up in March 2023, including cosmetics giant [12]Lush and [13]Stanford University , which just this week admitted to a data leak of 27,000 people's information.

El Reg sent a request for comment to Nissan Oceania to seek comment on the possibility ransomware caused this incident, but it did not immediately respond. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfKEa80SVtuT7XcQwnV0xgAAAQ0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfKEa80SVtuT7XcQwnV0xgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfKEa80SVtuT7XcQwnV0xgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.nissan.com.au/website-update.html

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfKEa80SVtuT7XcQwnV0xgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/02/06/akira_and_8base_new_ransomware_research/

[7] https://www.theregister.com/2024/03/13/stanford_university_ransomware/

[8] https://www.theregister.com/2024/03/12/leicester_city_council_stays_shtum/

[9] https://www.theregister.com/2023/09/25/car_industry_brexit_tariff/

[10] https://www.theregister.com/2023/10/17/nhtsa_cruise_investigation/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfKEa80SVtuT7XcQwnV0xgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://forums.theregister.com/forum/all/2024/01/26/akira_lush_ransomware/

[13] https://www.theregister.com/2024/03/13/stanford_university_ransomware/

[14] https://whitepapers.theregister.com/



sanmigueelbeer

Oh what a feeling ...

xyz123

Short version - Nissan execs sell customer data to scammers, claim its not their fault.

cornetman

> Among the data stolen from the automotive manufacturer was info on 4,000 Medicare cards - Australia's national health insurance scheme - plus 7,500 driving licenses, 220 passports, and 1,300 tax file numbers.

It wasn't clear to me if the data belonged to customers or employees of the company.

If it were customers, I don't really understand why a car manufacturer would have these types of information.

Yorick Hunt

"I don't really understand why a car manufacturer would have these types of information"

Vendor-financed car loans.

The more pertinent question is, why would they need to retain this information after the loan approval process has been completed?

Diogenes

The more pertinent question is, why would they need to retain this information after the loan approval process has been completed?

When the inevitable " you shouldn't have given me this loan which I can obviously can't afford" lawsuit, Financial ombudsma, Royal Commissionn etc complaints come in

Anonymous Coward

So they can sell it, obviously.

Kafka's Law:
In the fight between you and the world, back the world.
-- Franz Kafka, "RS's 1974 Expectation of Days"