SHINDO5

Nissan

Personal data~21,000people

LEAK CONFIRMEDPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Dec 23, 2025
Detected
Sep 26, 2025
Detection to disclosure
88 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
ContactAddress, Phone number, Part of email addresses
Transactions & activityRelated information used for sales activities

How many

  • Nissan Fukuoka Sales customers ~21,000 people

Who is affected

  • Customers who bought vehicles or used services

Cause

A data server of Red Hat, contracted to develop the customer management system used by dealers, was hit by a cyberattack

Timeline

  1. Red Hat detected the breach
  2. Red Hat reported to Nissan
  3. First disclosure

Response

  • Notified individuals
  • Phishing warning

Contacted affected customers to explain and warn them

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources