Data Breaches

Nissan Confirms Impact From Red Hat Data Breach

The personal information of 21,000 customers was stolen after hackers compromised Red Hat’s GitLab instances.

Nissan data breach

Japanese car maker Nissan has disclosed the impact of a data breach involving a self-managed GitLab instance used by the Red Hat Consulting team.

The incident leading to the Nissan data breach occurred in late September and involved unauthorized access to a GitLab instance containing example code snippets, internal communications, and project specifications.

A hacking group named Crimson Collective attempted to extort Red Hat, claiming the theft of 570 Gb of compressed data from 28,000 private repositories, including information that allegedly provided access to Red Hat customers’ infrastructure.

Nissan now says that some of the data stolen from Red Hat’s instances included personal information of 21,000 customers of Nissan Fukuoka Sales (previously Fukuoka Nissan Motor).

The personal information, the car maker says, includes names, addresses, phone numbers, partial email addresses, and information used for sales activities.

No credit card data was stolen, and no other customer information was stored in the compromised repository, Nissan says.

Advertisement. Scroll to continue reading.

The company says that Red Hat notified it of the incident on October 3, roughly a week after the attack occurred.

“Nissan received a report from RedHat, which had outsourced the development of a customer management system for a sales company, that it had unauthorized access to its data servers and leaked data,” an automated translation of Nissan’s incident notice reads.

The Japanese company says it has reported the incident to the relevant authorities, and has been notifying the individuals impacted by the data breach.

Nissan also notes that it could not confirm reports that the stolen information might have been “used twice” by the threat actors.

Related: 3.5 Million Affected by University of Phoenix Data Breach

Related: University of Sydney Data Breach Affects 27,000 Individuals

Related: 113,000 Impacted by Data Breach at Virginia Mental Health Authority

Related: 700Credit Data Breach Impacts 5.8 Million Individuals

Related Content

Data Breaches

Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version