Nissan Finance Canada Suffers a Data Breach
nissancanadafinance.ca
nissancanadafinance.ca
* They became aware of it Dec 11th – do they have an estimate of when this occurred?
* They mention what types of information has likely been affected, yet for some reason they mention “no payment details have been breached” right at the end of the Q&A? I’d have expected that to be much higher up the announcement.
* Not needed in the general announcement, but knowing how is always a point of interest (that may just be me, being in the business) – third party? SQLi? etc.
* How did they become aware of this? Did they discover this internally? Or did an outsider give them the heads up.
I’d like to think that one day, that last question can be answered by my startup[0], detecting breaches with a high degree of confidence with pseudo/honey users.
If that turns out to really be the only affected info, does this actually have identity theft implications? It compromises access to NCF accounts, I suppose, but while there's some info that would normally be private (loan amounts, credit score), I don't see any truly sensitive info here. Notably, no SIN, work info, income amounts, or other things you'd expect on a credit application.
Basically, as of now it looks like the post-approval payment tracking system got breached, not the actual approval system.
(Disclaimer: no ownership in either)
BUT... do it wrong and business will adapt in malignant ways, like folding and restarting, or spinning off the liability.
I would like to hire you as VP of Public Relations for my company.