In early 2026, Nissan North America, Inc., a subsidiary of Nissan Motor Co., Ltd., announced it was investigating a cybersecurity incident. A ransomware group reportedly exfiltrated 910 GB of data. Nissan publicly acknowledged potential unauthorized access to its IT systems on February 15, 2026, following extortion threats. The company began notifying affected individuals by March 2026.
The confirmed data types exposed include full names, home addresses, email addresses, phone numbers, dates of birth, Social Security numbers (SSNs), driver's license numbers, passport numbers, financial account details, and health insurance details. Additionally, vehicle identification numbers (VINs), geolocation data, and full service histories were compromised. Approximately 220,342 individuals in the US were notified, primarily current and former employees, contractors, and their dependents. The full scope of affected individuals globally may be up to 1.2 million, but US notifications are the primary focus. Nissan has stated no evidence suggests an impact on vehicle safety systems.
More details may emerge as investigations proceed, and some individuals may experience delayed notification.