The Akira ransomware group asserted that it had gained access to Nissan Australia and had taken around 100GB of material from the massive automaker.
The ransomware group threatened to release the purportedly stolen documents, which included project data, client and partner information, and nondisclosure agreements (NDAs), if the organisation did not pay the ransom.
Nissan has already given notice to the National Cyber Security Centre of New Zealand and the Australian Cyber Security Centre.
The attack's extent and other specifics were not disclosed by the company. Nissan is currently looking into the event to find out how big of a data breach it was.
Source: https://securityaffairs.com/156283/cyber-crime/akira-ransomware-breached-nissan-australia.html
TPRM report: https://scoringcyber.rankiteo.com/company/nissan-financial-services-australia-pty-ltd
"id": "nis142251223",
"linkid": "nissan-financial-services-australia-pty-ltd",
"type": "Ransomware",
"date": "12/2023",
"severity": "75",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'industry': 'Automotive',
'location': 'Australia',
'name': 'Nissan Australia',
'type': 'Company'}],
'data_breach': {'data_exfiltration': True,
'type_of_data_compromised': ['Project Data',
'Client and Partner Information',
'Nondisclosure Agreements '
'(NDAs)']},
'description': 'The Akira ransomware group claimed to have accessed Nissan '
"Australia's systems and stolen approximately 100GB of data. "
'The group threatened to release the stolen documents, '
'including project data, client and partner information, and '
'nondisclosure agreements (NDAs), if the ransom was not paid. '
'Nissan has notified the National Cyber Security Centre of New '
'Zealand and the Australian Cyber Security Centre. The company '
'is investigating the extent of the data breach.',
'impact': {'data_compromised': ['Project Data',
'Client and Partner Information',
'Nondisclosure Agreements (NDAs)']},
'investigation_status': 'Ongoing',
'motivation': 'Financial Gain',
'ransomware': {'data_exfiltration': True,
'ransom_demanded': True,
'ransomware_strain': 'Akira'},
'regulatory_compliance': {'regulatory_notifications': ['National Cyber '
'Security Centre of '
'New Zealand',
'Australian Cyber '
'Security Centre']},
'response': {'law_enforcement_notified': ['National Cyber Security Centre of '
'New Zealand',
'Australian Cyber Security Centre']},
'threat_actor': 'Akira Ransomware Group',
'title': 'Akira Ransomware Attack on Nissan Australia',
'type': 'Ransomware Attack'}