Skip to main content
Back to overview
Medium

Nissan Confirms Impact From Red Hat Data Breach, 21,000 Customers Affected

Japanese car maker Nissan has disclosed the impact of a data breach involving a self-managed GitLab instance used by the Red Hat Consulting team.

Key points

  • Approximately 21,000 Nissan customers affected.
  • Exposed data includes names, addresses, phone numbers, partial email addresses, and sales-related customer data.
  • Breach originated from unauthorized access to a Red Hat-managed GitLab server used by Nissan's third-party vendor.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Dec 23, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

NissanData DisclosureNissan Confirms Impact From RedCustomers Affected JapaneseNissanGitLabRed Hat ConsultingSeptember andCrimson CollectiveRed Hat

Quick context

Questions about this signal

What happened in this signal?

Japanese car maker Nissan has disclosed the impact of a data breach involving a self-managed GitLab instance used by the Red Hat Consulting team. The incident leading to the Nissan data breach occurred in late September and involved unauthorized access to a GitLab instance containing example code snippets, internal communications, and project specifications. A hacking group named Crimson Collective attempted to extort Red Hat, claiming the theft of 570 Gb of compressed data from 28,000 private repositories, including information that allegedly provided access to Red Hat customers’ infrastructure. Nissan now says that some of the data stolen from Red Hat’s instances included personal information of 21,000 customers of Nissan Fukuoka Sales (previously Fukuoka Nissan Motor). The personal information, the car maker says, includes names, addresses, phone numbers, partial email addresses, and information used for sales activities. No credit card data was stolen, and no other customer information was stored in the compromised repository, Nissan says. Advertisement. Scroll to continue reading. The company says that Red Hat notified it of the incident on October 3, roughly a week after the attack occurred. “Nissan received a report from RedHat, which had outsourced the development of a customer management system for a sales company, that it had unauthorized access to its data servers and leaked data,” an automated translation of Nissan’s incident notice reads. The Japanese company says it has reported the incident to the relevant authorities, and has been notifying the individuals impacted by the data breach. Nissan also notes that it could not confirm reports that the stolen information might have been “used twice” by the threat actors. Related: 3.5 Million Affected by University of Phoenix Data Breach Related: University of Sydney Data Breach Affects 27,000 Individuals Related: 113,000 Impacted by Data Breach at Virginia Mental Health Authority Related: 700Credit Data Breach Impacts 5.8 Million Individuals Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

When was this signal reported?

Shadow Tier lists Dec 23, 2025 as the signal date.

Which organization is connected to this signal?

Nissan is the organization connected to this public signal.

Explore Nissan
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence