Nissan Confirms Employee Data Breach Tied to Oracle PeopleSoft Zero-Day

Nissan is warning current and former employees that their personal data was stolen in a breach linked to attacks on Oracle PeopleSoft systems. The company says attackers exploited a vulnerability in the software it uses for payroll, tax administration, and personnel records.

The automaker doesn’t yet know the full scope, but says exposed data may include contact information, banking details, Social Security numbers, financial and tax records, and dependent information. The incident appears to affect employees in the US, Canada, Mexico, and Brazil. Nissan says it’s still in the early stages of investigation.

The breach notification, filed with the California Attorney General’s Office, says Oracle informed Nissan that “hundreds of companies may have been obtained by so-called threat actors” and that Nissan was specifically targeted. Nissan has brought in external cybersecurity experts, secured affected systems, and is working with Oracle to address the vulnerability.

As a precaution, the company is restricting access to pay slips and direct deposit changes to company network computers or secured VPN connections. Affected individuals will get free credit and dark web monitoring where available.

The attack is linked to the ShinyHunters extortion group, which has claimed responsibility for exploiting a zero-day flaw in Oracle PeopleSoft PeopleTools — tracked as CVE-2026-35273. Mandiant confirmed the vulnerability was exploited as a zero-day between May 27 and June 9, primarily targeting education sector organizations. ShinyHunters claimed over 300 PeopleSoft instances across 100 organizations were breached. Oracle released emergency mitigations after disclosure.

References