Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Nissan Source Code Leak 2021: How a Git…
Breach analysis Incident: 4 Jan 2021

Nissan Source Code Leak 2021: How a Git Server Left on admin/admin Exposed 20GB of Code

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
On this page

In the first week of January 2021, around 20GB of source code belonging to Nissan North America began circulating on Telegram and hacking forums. The code came from a company Git server, a Bitbucket instance, that had been left reachable from the internet with its default username and password, admin/admin. Swiss software engineer Tillie Kottmann said an anonymous source pointed them to the server, that they downloaded the data themselves, and they publicised it on Monday 4 January 2021. The repositories held code for Nissan's mobile apps, parts of its ASIST diagnostics tool, dealer portals, connected vehicle services, logistics and marketing tools. Nissan confirmed it was investigating "improper access to proprietary company source code" and said the affected system had been secured, that no personal data of consumers, dealers or employees was accessible and that the code posed no risk to vehicles. No source has confirmed that secrets in the code were misused.

Key takeaways

  • A Nissan North America Git server was reachable from the internet with the default login admin/admin, according to Computing, CyberScoop and Flare.
  • The default account was used to clone about 20GB of source code for mobile apps, diagnostics, dealer, logistics and connected vehicle systems, which then spread as a torrent.
  • Nissan said it secured the system and that no personal data of consumers, dealers or employees was accessible; Flare found limited interest in the leak on criminal forums.
  • Tillie Kottmann publicised the leak on 4 January 2021; Kottmann was indicted in the US in March 2021 over a wider series of alleged intrusions; the indictment does not name Nissan, and Kottmann is presumed innocent unless proven guilty.
  • The identity lesson: a default, shared administrator login on a machine is a non-human credential with no owner, and it should never survive installation.

At a glance

OrganisationNissan North America
WhenServer exposure date unknown; leak publicised on 4 January 2021; first reported by ZDNet on 6 January 2021
AttackerUnnamed source who tipped off Swiss software engineer Tillie Kottmann, who downloaded and published the data
Entry pointAn internet-facing Bitbucket Git server left on its default admin/admin login
Identities abusedThe server's default, shared administrator account
ImpactAbout 20GB of proprietary source code leaked and shared by torrent; Nissan said no personal data was accessible
CategoryNHI. Incident class: confirmed NHI breach (default shared admin login used to clone and leak source code)

What happened

Tillie Kottmann, a Swiss software engineer known for publishing leaked source code from misconfigured development servers, said they were told about a Nissan North America server by an anonymous source. "I was informed about the server by an anonymous source but acquired it myself and can thus mostly verify it," Kottmann told CyberScoop, describing it as "severely mismanaged". According to Computing, the server "was left exposed online with a default username and password (admin/admin)." Flare, which also reviewed the case, identified it as a Bitbucket instance.

Kottmann published the material on Twitter and Telegram. CyberScoop reported that "On Monday, Kottmann said the server exposed a broad range of data", which was 4 January 2021, and that ZDNet first reported the story on Wednesday 6 January. According to Security Affairs and Dark Reading, engineers who reviewed the repositories found code for Nissan North America's mobile apps, parts of the ASIST diagnostics tool, dealer business systems and the dealer portal, Nissan's internal core mobile library, Nissan and Infiniti NCAR/ICAR services, client acquisition and retention tools, sales and market research tools, a vehicle logistics portal, connected vehicle services and various back ends and internal tools. Hackread and Flare put the collection at about 20GB.

Torrent links spread on Telegram channels and hacking forums, and the server was taken offline. Flare looked at the criminal reaction a week later and found it muted: the torrent had been seeded by 91 users and downloaded by another 103, and one forum user complained the leak held "nothing of critical importance".

Nissan first said it was "aware of a claim regarding a reported improper disclosure of Nissan's confidential information and source code," adding: "We take this type of matter seriously and are conducting an investigation," according to Computing. Two days later a spokesperson told CyberScoop: "Nissan conducted an immediate investigation regarding improper access to proprietary company source code," and "The affected system has been secured". Nissan said no personal data from consumers, dealers or employees was accessible and that the code did not put consumers or their vehicles at risk. Kottmann then told CyberScoop they could still reach "other" Nissan resources, a claim Nissan did not confirm in the sources we read.

Timeline

DateEvent
4 January 2021Tillie Kottmann publicises the Nissan North America source code on Twitter and Telegram.
6 January 2021ZDNet first reports the leak; Nissan says it is investigating.
7 January 2021Dark Reading and Computing report the default admin/admin login and Nissan's statement.
8 January 2021Nissan tells CyberScoop the affected system has been secured; Kottmann says other Nissan resources are still reachable.
13 January 2021Flare reports limited interest in the leak on criminal forums.
18 March 2021The US Attorney's Office in Seattle announces the indictment of Till Kottmann over alleged source code thefts; it mentions an unnamed automobile manufacturer targeted in January 2021 but does not name Nissan.

How it happened: the identity attack path

  1. Exposed source-control server. A Nissan North America Bitbucket server was reachable from the internet rather than only from the corporate network.
  2. Default administrator login. The server still accepted the factory default credentials admin/admin, a shared account that belonged to no individual and was never rotated.
  3. Repository cloning. An anonymous source, and then Kottmann, logged in with the default account and copied about 20GB of repositories.
  4. Public release. The code was posted to Telegram and shared on hacking forums as a torrent, putting it beyond Nissan's control.
  5. Containment. Nissan took the server offline and said the affected system was secured.

Impact

  • Confirmed: Nissan confirmed improper access to proprietary source code and secured the system. The code covered mobile apps, diagnostics, dealer, logistics, marketing and connected vehicle systems.
  • Personal data: Nissan said no personal data from consumers, dealers or employees was accessible.
  • Claimed: Kottmann said they could still access other Nissan resources after the server was secured. This was not confirmed by Nissan in the sources we read.
  • Potential: leaked source code can reveal weaknesses in apps and back ends, and any credentials committed to it. No source confirmed secrets in the Nissan code or their misuse.

What this means for NHI governance

A default login is not a person. The admin/admin account on Nissan's Git server was a shared, built-in credential that came with the product, had no named owner and, judging by its value, had never been changed. That makes it a non-human identity in practice: a standing credential with administrator rights over the company's code, held by nobody and therefore watched by nobody. We list it here for the same reason we list the McHire default password case. The identity failure was not a phished employee but an ownerless account that anyone could guess.

Source-control servers deserve particular care because they are where other secrets end up. The United Nations and Indian Government cases from early 2021 show how code repositories often carry database passwords and API keys, so an exposed repository can quickly become an exposed credential store. Removing default accounts, putting source control behind single sign-on and MFA, and scanning repositories for secrets would each have narrowed this incident. Our Service Account Security Guide and Secrets Management Guide cover these controls.

Recommendations

  • Remove or change every default account at installation. Make credential change part of the build checklist for servers and appliances, and scan for default logins on a schedule. See our Password Security Guide.
  • Keep source-control servers off the open internet. Put self-hosted Git behind a VPN or zero trust access proxy and require single sign-on with MFA for every login. See our Zero Trust Identity Guide.
  • Give every privileged account a named owner. Shared administrator accounts should be inventoried, owned and vaulted, with logins monitored. See our NHI Ownership Guide.
  • Scan repositories for secrets and treat leaked code as leaked credentials. When code escapes, rotate every key, token and password it contains. See the Leaked Credential Response Playbook.
  • Find shadow development servers. Discover self-hosted Git, CI and artefact servers across the estate so none run outside security policy.
  • Alert on bulk repository cloning. Large clone or archive activity from unfamiliar addresses is an early sign of theft.

Frequently asked questions

How was Nissan's source code leaked in 2021?

A Nissan North America Bitbucket Git server was reachable from the internet with the default username and password admin/admin. Someone used that login to download about 20GB of repositories, which Tillie Kottmann then published on 4 January 2021 and which spread as a torrent on Telegram and hacking forums.

Was customer data exposed in the Nissan source code leak?

Nissan said no personal data from consumers, dealers or employees was accessible and that the exposed code posed no risk to consumers or their vehicles. The leak was proprietary source code for apps, diagnostics, dealer, logistics and connected vehicle systems.

Why is a default admin password an NHI problem?

A default login such as admin/admin is a shared credential built into a product, not an account belonging to a person. Without an owner it is rarely changed or monitored, so it behaves like any other unmanaged machine credential: whoever finds it inherits its access.

Verkada Camera Breach 2021 · Mercedes-Benz Source Code Leak 2020 · McHire Default Password Flaw 2025 · Service Account Security Guide · Secrets Management Guide

How NHI Mgmt Group can help

Default logins, shared admin accounts and forgotten development servers appear again and again in our breach database. We help organisations find these ownerless credentials, assign owners, vault or remove them and keep source control behind strong authentication. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org