01Summary
Between 27 May and 9 June 2026, threat actors exploited the critical Oracle PeopleSoft vulnerability CVE-2026-35273. Nissan was among the organisations affected. The company was informed by Oracle of a cyber event impacting personnel records of hundreds of companies and later determined that Nissan had been specifically targeted. Exposed data may include contact information, banking details, Social Security / Social Insurance / national ID numbers, financial and tax records, and dependent/beneficiary information belonging to current and former employees in the US, Canada, Mexico and Brazil. Exact number of affected individuals has not been publicly disclosed. Nissan activated incident response, engaged external experts, and implemented additional controls around payroll access.
02Background
Nissan uses Oracle PeopleSoft for employee information management, including payroll, tax administration and personnel records across its Americas operations.
03Key revelations
- 01Nissan was specifically targeted within a wider opportunistic PeopleSoft zero-day campaign.
- 02Highly sensitive employee payroll, tax and identity data was at risk.
04Technical analysis
Part of the broader ShinyHunters campaign exploiting CVE-2026-35273 (critical unauthenticated RCE in Oracle PeopleSoft PeopleTools / Environment Management components). The campaign targeted approximately 100 organisations / 300 instances, with a heavy focus on higher education but also hitting corporate victims such as Nissan.
- Attack vector
- Exploitation of Oracle PeopleSoft zero-day (CVE-2026-35273)
- Attack method
- Remote code execution and data exfiltration
- Initial access
- Exploitation of Public-Facing Application
- Exfiltration
- Data extraction from PeopleSoft environment
Vulnerabilities exploited
- CVE-2026-35273
05Threat actor
ShinyHunters is a prolific cybercriminal/extortion group known for large-scale data theft and 'pay or leak' operations, frequently targeting enterprise platforms.
Aliases
- SH
- UNC6240
Attribution sources
- Link to broader ShinyHunters PeopleSoft campaign (CVE-2026-35273)
- Mandiant / Google Threat Intelligence reporting
- Nissan breach notifications
- Media reports
06Victims and impact
Additional victims
- Current and former employees in the United States, Canada, Mexico, and Brazil
Countries affected
- United States
- Canada
- Mexico
- Brazil
07Data exposed
Data types
- PII
- Contact information
- Banking information
- Social Security / Social Insurance / National ID numbers
- Financial and tax information
- Dependent and beneficiary information
08Financial damage
Incident response, forensic, notification and monitoring costs; potential regulatory and civil exposure.
09Timeline
- 2026-05-27Start of observed exploitation window for CVE-2026-35273.
- 2026-06-09End of primary exploitation window.
- 2026-06-25Nissan files breach notification / becomes aware of specific targeting.
- 2026-06-29Public reporting of the Nissan disclosure.
10Reaction and fallout
Public reaction
Concern among current and former employees over exposure of SSNs, banking and tax data.
11Legal
Notifications filed with state authorities; investigation ongoing at time of disclosure. Credit and dark web monitoring offered where available.
12Aftermath
Security improvements
- Incident response activated
- External cybersecurity experts engaged
- Stricter controls on payroll and direct-deposit changes (corporate network/VPN + additional identity verification)
13Significance and legacy
Significance
Corporate victim of the 2026 ShinyHunters Oracle PeopleSoft zero-day campaign, notable for the sensitivity of HR/payroll data exposed.
14Disclosure and media
Publishing organisations
- The Register
- BleepingComputer
- SecurityWeek
- ClassAction.org
16Field notes
- 01Part of a campaign that hit roughly 100 organisations and 300 PeopleSoft instances.
- 02Nissan implemented extra verification steps specifically for payroll and direct-deposit changes after the incident.
17Resolution
Systems secured after discovery. Full impact assessment and individual notifications continued after public disclosure in late June 2026.
18Sources
Official documents
- Nissan Americas breach notifications filed with California Attorney General
References
- [1]Nissan breach notifications
- [2]The Register
- [3]BleepingComputer
- [4]SecurityWeek
- [5]Mandiant / Google reporting on the wider campaign









