In the first week of January 2021, around 20GB of source code belonging to Nissan North America began circulating on Telegram and hacking forums. The code came from a company Git server, a Bitbucket instance, that had been left reachable from the internet with its default username and password, admin/admin. Swiss software engineer Tillie Kottmann said an anonymous source pointed them to the server, that they downloaded the data themselves, and they publicised it on Monday 4 January 2021. The repositories held code for Nissan's mobile apps, parts of its ASIST diagnostics tool, dealer portals, connected vehicle services, logistics and marketing tools. Nissan confirmed it was investigating "improper access to proprietary company source code" and said the affected system had been secured, that no personal data of consumers, dealers or employees was accessible and that the code posed no risk to vehicles. No source has confirmed that secrets in the code were misused.
Key takeaways
- A Nissan North America Git server was reachable from the internet with the default login admin/admin, according to Computing, CyberScoop and Flare.
- The default account was used to clone about 20GB of source code for mobile apps, diagnostics, dealer, logistics and connected vehicle systems, which then spread as a torrent.
- Nissan said it secured the system and that no personal data of consumers, dealers or employees was accessible; Flare found limited interest in the leak on criminal forums.
- Tillie Kottmann publicised the leak on 4 January 2021; Kottmann was indicted in the US in March 2021 over a wider series of alleged intrusions; the indictment does not name Nissan, and Kottmann is presumed innocent unless proven guilty.
- The identity lesson: a default, shared administrator login on a machine is a non-human credential with no owner, and it should never survive installation.
At a glance
| Organisation | Nissan North America |
|---|---|
| When | Server exposure date unknown; leak publicised on 4 January 2021; first reported by ZDNet on 6 January 2021 |
| Attacker | Unnamed source who tipped off Swiss software engineer Tillie Kottmann, who downloaded and published the data |
| Entry point | An internet-facing Bitbucket Git server left on its default admin/admin login |
| Identities abused | The server's default, shared administrator account |
| Impact | About 20GB of proprietary source code leaked and shared by torrent; Nissan said no personal data was accessible |
| Category | NHI. Incident class: confirmed NHI breach (default shared admin login used to clone and leak source code) |
What happened
Tillie Kottmann, a Swiss software engineer known for publishing leaked source code from misconfigured development servers, said they were told about a Nissan North America server by an anonymous source. "I was informed about the server by an anonymous source but acquired it myself and can thus mostly verify it," Kottmann told CyberScoop, describing it as "severely mismanaged". According to Computing, the server "was left exposed online with a default username and password (admin/admin)." Flare, which also reviewed the case, identified it as a Bitbucket instance.
Kottmann published the material on Twitter and Telegram. CyberScoop reported that "On Monday, Kottmann said the server exposed a broad range of data", which was 4 January 2021, and that ZDNet first reported the story on Wednesday 6 January. According to Security Affairs and Dark Reading, engineers who reviewed the repositories found code for Nissan North America's mobile apps, parts of the ASIST diagnostics tool, dealer business systems and the dealer portal, Nissan's internal core mobile library, Nissan and Infiniti NCAR/ICAR services, client acquisition and retention tools, sales and market research tools, a vehicle logistics portal, connected vehicle services and various back ends and internal tools. Hackread and Flare put the collection at about 20GB.
Torrent links spread on Telegram channels and hacking forums, and the server was taken offline. Flare looked at the criminal reaction a week later and found it muted: the torrent had been seeded by 91 users and downloaded by another 103, and one forum user complained the leak held "nothing of critical importance".
Nissan first said it was "aware of a claim regarding a reported improper disclosure of Nissan's confidential information and source code," adding: "We take this type of matter seriously and are conducting an investigation," according to Computing. Two days later a spokesperson told CyberScoop: "Nissan conducted an immediate investigation regarding improper access to proprietary company source code," and "The affected system has been secured". Nissan said no personal data from consumers, dealers or employees was accessible and that the code did not put consumers or their vehicles at risk. Kottmann then told CyberScoop they could still reach "other" Nissan resources, a claim Nissan did not confirm in the sources we read.
Timeline
| Date | Event |
|---|---|
| 4 January 2021 | Tillie Kottmann publicises the Nissan North America source code on Twitter and Telegram. |
| 6 January 2021 | ZDNet first reports the leak; Nissan says it is investigating. |
| 7 January 2021 | Dark Reading and Computing report the default admin/admin login and Nissan's statement. |
| 8 January 2021 | Nissan tells CyberScoop the affected system has been secured; Kottmann says other Nissan resources are still reachable. |
| 13 January 2021 | Flare reports limited interest in the leak on criminal forums. |
| 18 March 2021 | The US Attorney's Office in Seattle announces the indictment of Till Kottmann over alleged source code thefts; it mentions an unnamed automobile manufacturer targeted in January 2021 but does not name Nissan. |
How it happened: the identity attack path
- Exposed source-control server. A Nissan North America Bitbucket server was reachable from the internet rather than only from the corporate network.
- Default administrator login. The server still accepted the factory default credentials admin/admin, a shared account that belonged to no individual and was never rotated.
- Repository cloning. An anonymous source, and then Kottmann, logged in with the default account and copied about 20GB of repositories.
- Public release. The code was posted to Telegram and shared on hacking forums as a torrent, putting it beyond Nissan's control.
- Containment. Nissan took the server offline and said the affected system was secured.
Impact
- Confirmed: Nissan confirmed improper access to proprietary source code and secured the system. The code covered mobile apps, diagnostics, dealer, logistics, marketing and connected vehicle systems.
- Personal data: Nissan said no personal data from consumers, dealers or employees was accessible.
- Claimed: Kottmann said they could still access other Nissan resources after the server was secured. This was not confirmed by Nissan in the sources we read.
- Potential: leaked source code can reveal weaknesses in apps and back ends, and any credentials committed to it. No source confirmed secrets in the Nissan code or their misuse.
What this means for NHI governance
A default login is not a person. The admin/admin account on Nissan's Git server was a shared, built-in credential that came with the product, had no named owner and, judging by its value, had never been changed. That makes it a non-human identity in practice: a standing credential with administrator rights over the company's code, held by nobody and therefore watched by nobody. We list it here for the same reason we list the McHire default password case. The identity failure was not a phished employee but an ownerless account that anyone could guess.
Source-control servers deserve particular care because they are where other secrets end up. The United Nations and Indian Government cases from early 2021 show how code repositories often carry database passwords and API keys, so an exposed repository can quickly become an exposed credential store. Removing default accounts, putting source control behind single sign-on and MFA, and scanning repositories for secrets would each have narrowed this incident. Our Service Account Security Guide and Secrets Management Guide cover these controls.
Recommendations
- Remove or change every default account at installation. Make credential change part of the build checklist for servers and appliances, and scan for default logins on a schedule. See our Password Security Guide.
- Keep source-control servers off the open internet. Put self-hosted Git behind a VPN or zero trust access proxy and require single sign-on with MFA for every login. See our Zero Trust Identity Guide.
- Give every privileged account a named owner. Shared administrator accounts should be inventoried, owned and vaulted, with logins monitored. See our NHI Ownership Guide.
- Scan repositories for secrets and treat leaked code as leaked credentials. When code escapes, rotate every key, token and password it contains. See the Leaked Credential Response Playbook.
- Find shadow development servers. Discover self-hosted Git, CI and artefact servers across the estate so none run outside security policy.
- Alert on bulk repository cloning. Large clone or archive activity from unfamiliar addresses is an early sign of theft.
Frequently asked questions
How was Nissan's source code leaked in 2021?
A Nissan North America Bitbucket Git server was reachable from the internet with the default username and password admin/admin. Someone used that login to download about 20GB of repositories, which Tillie Kottmann then published on 4 January 2021 and which spread as a torrent on Telegram and hacking forums.
Was customer data exposed in the Nissan source code leak?
Nissan said no personal data from consumers, dealers or employees was accessible and that the exposed code posed no risk to consumers or their vehicles. The leak was proprietary source code for apps, diagnostics, dealer, logistics and connected vehicle systems.
Why is a default admin password an NHI problem?
A default login such as admin/admin is a shared credential built into a product, not an account belonging to a person. Without an owner it is rarely changed or monitored, so it behaves like any other unmanaged machine credential: whoever finds it inherits its access.
Related NHI Mgmt Group resources
Verkada Camera Breach 2021 · Mercedes-Benz Source Code Leak 2020 · McHire Default Password Flaw 2025 · Service Account Security Guide · Secrets Management Guide
How NHI Mgmt Group can help
Default logins, shared admin accounts and forgotten development servers appear again and again in our breach database. We help organisations find these ownerless credentials, assign owners, vault or remove them and keep source control behind strong authentication. See our NHI and AI agent security training.
References
- CyberScoop: Nissan investigated source code exposure, says it plugged leak (6 January 2021)
- Dark Reading: Nissan Source Code Leaked via Misconfigured Git Server (7 January 2021)
- Computing: Nissan suffers data leak via misconfigured Git server (7 January 2021)
- Security Affairs: Unsecured Git server exposed Nissan North America (8 January 2021)
- Hackread: Nissan source code leaked after it used "admin" as username, password (8 January 2021)
- Flare: Malicious Actors Show Little Interest in Automotive Source Code Leak (13 January 2021)
- US Department of Justice: Swiss Hacker indicted for conspiracy, wire fraud, and aggravated identity theft (18 March 2021)