HomeYoutubeNissan: Employee data breach via Oracle PeopleSoft vulnerability

Nissan: Employee data breach via Oracle PeopleSoft vulnerability

Nissan it is investigating a serious cybersecurity incident that may have led to the breach of personal data of current and former employees. According to the company, the attack is linked to the exploitation of a critical vulnerability in the Oracle PeopleSoft, one of the most widely used human resources and payroll systems for large organizations.

The case adds to the ever-growing list of attacks targeting business-critical corporate applications, highlighting the risks created when vulnerabilities are identified in software used by hundreds of businesses worldwide.

Nissan among companies targeted

In disclosures filed with California authorities, Nissan says it was notified by Oracle of a cyberattack that may have affected hundreds of organizations. The automaker says it was one of the specific targets of the campaign.

See also: Oracle E-Business Suite: Vulnerability used in attacks

Oracle PeopleSoft is used by Nissan Americas to manage critical personnel information, such as payroll data, tax data and employee records. While the investigation is still ongoing, initial indications are that the attackers may have gained access to sensitive personal information.

The information that may have been exposed includes contact information, bank accounts, social security and national identity numbers, tax and financial data, as well as information regarding dependents and beneficiary information.

Nissan Data Breach

Who is affected by the incident?

Nissan estimates that the incident affects current and former employees in the United States, Canada, Mexico and Brazil. The exact number of people affected has not yet been released as the assessment process continues.

The company clarifies that those found to have been affected will receive personalized updates with detailed information about the data that was exposed, while they will also have access to credit activity monitoring and dark web data tracking services , where these are available.

The measures taken by the automotive industry

Upon learning of the breach, Nissan immediately activated its security incident response plan, hired specialized cybersecurity consultants, isolated affected systems, and is working closely with Oracle to fully investigate the incident.

Nissan: Employee data breach via Oracle PeopleSoft vulnerability

Additionally, the company has restricted access to payroll functions and bank deposit changes, allowing them to be performed only through company computers or secure VPN connections. At the same time, additional identity verification mechanisms are implemented before approving any related action, reducing the risk of further abuse.

See also: The renewed Millennium RAT has infected over 62,000 devices

The vulnerability exploited in the attacks

The incident is linked to the widespread exploitation of the CVE-2026-35273 vulnerability in Oracle PeopleSoft PeopleTools. This is a critical security flaw that was used as a zero-day, that is, before an official security update was released.

According to Mandiant, the attacks took place between May 27 and June 9, with attackers gaining access to corporate environments and removing data without being immediately noticed. Although Oracle deployed emergency protection measures, the vulnerability had already affected a significant number of organizations.

ShinyHunters' action and growing threats

The campaign was claimed by the ShinyHunters, which claims to have compromised more than 300 PeopleSoft environments across approximately 100 organizations. The group has gained a particular reputation in recent years for attacks targeting cloud services and SaaS platforms, with the primary goal of data theft and extortion through data leakage.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer

Nissan: Employee data breach via Oracle PeopleSoft vulnerability

The attacks were not limited to the automotive industry. According to reports, the education, while organizational data has already been published on leak websites. The incident is yet another reminder that businesses must promptly apply available security updates, invest in threat detection mechanisms and adopt cyber resilience strategies, as attacks on critical corporate platforms become increasingly targeted and sophisticated.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS