Nissan confirms employee data breach following Oracle PeopleSoft zero-day attack
- Evelyn Carter

- Jul 2
- 3 min read
Nissan has confirmed that current and former employee data may have been accessed after attackers exploited the Oracle PeopleSoft zero-day vulnerability, CVE-2026-35273. According to Oracle, the campaign affected hundreds of companies, while Mandiant said it notified more than 100 organizations impacted by the attacks.
Nissan has disclosed an employee data breach involving its Oracle PeopleSoft environment, following a large-scale cyber campaign that targeted organizations through a previously unknown vulnerability. The attacks have been linked to the ShinyHunters extortion group, which claimed responsibility for compromising numerous Oracle PeopleSoft instances.
How was nissan affected?
According to breach notifications filed with the California Attorney General's Office, Oracle informed Nissan that threat actors had conducted a cyberattack targeting Oracle PeopleSoft environments and may have obtained personnel records belonging to hundreds of organizations.
Nissan later confirmed that it was one of the organizations specifically targeted during the campaign.
The company uses Oracle PeopleSoft to manage employee-related operations, including payroll, tax administration, and personnel records.

What Employee Information May Have Been Exposed?
Nissan said its investigation is still in the early stages, and the full scope of the incident has not yet been determined.
However, the company believes the attackers may have accessed personal information that includes:
Employee contact information
Banking information
Social Security Numbers (SSNs)
Social Insurance Numbers (SINs) or National Identification Numbers
Financial and tax information
Dependent and beneficiary information
The incident is believed to affect current and former employees in the United States, Canada, Mexico, and Brazil.
How Is Nissan Responding?
After learning about the breach, Nissan activated its incident response procedures and engaged external cybersecurity specialists to investigate the incident. The company is also working closely with Oracle to address the issue.
According to Nissan, additional measures have been implemented to stop unauthorized access and reduce the risk of further data exposure.
As an additional precaution, Nissan has temporarily restricted access to employee pay slips and direct deposit changes to company-managed computers or secure VPN connections. The company has also introduced enhanced identity verification procedures before processing payroll-related requests.
How is this incident connected to the Oracle PeopleSoft campaign?
The disclosure is believed to be part of the widespread exploitation of Oracle PeopleSoft servers reported earlier this month. Threat actors exploited a zero-day vulnerability to compromise Oracle PeopleSoft environments and steal sensitive data from affected organizations.
Oracle subsequently disclosed the critical Oracle PeopleSoft PeopleTools vulnerability CVE-2026-35273 and released emergency mitigation guidance.
Although Oracle has not publicly confirmed that the vulnerability was actively exploited, Mandiant later verified that attackers used CVE-2026-35273 as a zero-day vulnerability in data theft attacks carried out between May 27 and June 9.
What role did ShinyHunters play?
The ShinyHunters extortion group claimed responsibility for the attacks, stating that more than 300 Oracle PeopleSoft instances across approximately 100 organizations had been compromised.
Since then, the group has begun publishing stolen data on its leak site, including information allegedly taken from the University of Nottingham and the National Association of Insurance Commissioners (NAIC).
Separately, ShinyHunters was also linked to a cyberattack against Instructure Canvas, in which approximately 280 million student, teacher, and staff records were reportedly stolen. According to the original report, Instructure later paid a ransom to prevent the stolen data from being released.
What is the solution for protecting an organization's digital shield?
To ensure enterprise systems remain protected against the increasingly complex global cybersecurity landscape, organizations should consider working with trusted cybersecurity and IT service providers.

IPSIP Vietnam provides comprehensive cybersecurity and IT services designed to help businesses strengthen their security posture and respond effectively to emerging threats.
IPSIP Vietnam's management and monitoring systems have successfully passed rigorous assessments to achieve internationally recognized ISO 27001:2022 and SOC 2 Type II information security certifications. Through its core 24/7 services, including a Security Operations Center (SOC 24/7), a Network Operations Center (NOC 24/7), and dedicated IT support and helpdesk teams, IPSIP is committed to continuously monitoring, responding to, and blocking cyber intrusion attempts around the clock.
Nissan's disclosure highlights the growing impact of the CVE-2026-35273 Oracle PeopleSoft zero-day campaign, which has affected numerous organizations across multiple sectors. The company continues to investigate the incident while implementing additional safeguards to protect employee information and mitigate further risks as the investigation progresses.
References











Comments