The Everest hacking group claims to have stolen 910 GB from a file-transfer system used by a vendor servicing Nissan and Infiniti dealerships across North America. Nissan says its own systems were not compromised and customer data was not accessed. This breach highlights the risk of third-party vendor data exposure in dealership ecosystems. Even if the principal company’s environment remains secure, sensitive customer and loan information can be exfiltrated through vendor systems without triggering direct compromise alerts. Security teams should verify vendor data controls and investigate potential lateral impacts across dealership networks.
Part of the PlainSec briefing for 2026-04-02