Nissan it is investigating a serious cybersecurity incident that may have led to the breach of personal data of current and former employees. According to the company, the attack is linked to the exploitation of a critical vulnerability in the Oracle PeopleSoft, one of the most widely used human resources and payroll systems for large organizations.
The case adds to the ever-growing list of attacks targeting business-critical corporate applications, highlighting the risks created when vulnerabilities are identified in software used by hundreds of businesses worldwide.
Nissan among companies targeted
In disclosures filed with California authorities, Nissan says it was notified by Oracle of a cyberattack that may have affected hundreds of organizations. The automaker says it was one of the specific targets of the campaign.
See also: Oracle E-Business Suite: Vulnerability used in attacks
Oracle PeopleSoft is used by Nissan Americas to manage critical personnel information, such as payroll data, tax data and employee records. While the investigation is still ongoing, initial indications are that the attackers may have gained access to sensitive personal information.
The information that may have been exposed includes contact information, bank accounts, social security and national identity numbers, tax and financial data, as well as information regarding dependents and beneficiary information.

Who is affected by the incident?
Nissan estimates that the incident affects current and former employees in the United States, Canada, Mexico and Brazil. The exact number of people affected has not yet been released as the assessment process continues.
The company clarifies that those found to have been affected will receive personalized updates with detailed information about the data that was exposed, while they will also have access to credit activity monitoring and dark web data tracking services , where these are available.
The measures taken by the automotive industry
Upon learning of the breach, Nissan immediately activated its security incident response plan, hired specialized cybersecurity consultants, isolated affected systems, and is working closely with Oracle to fully investigate the incident.

Additionally, the company has restricted access to payroll functions and bank deposit changes, allowing them to be performed only through company computers or secure VPN connections. At the same time, additional identity verification mechanisms are implemented before approving any related action, reducing the risk of further abuse.
See also: The renewed Millennium RAT has infected over 62,000 devices
The vulnerability exploited in the attacks
The incident is linked to the widespread exploitation of the CVE-2026-35273 vulnerability in Oracle PeopleSoft PeopleTools. This is a critical security flaw that was used as a zero-day, that is, before an official security update was released.
According to Mandiant, the attacks took place between May 27 and June 9, with attackers gaining access to corporate environments and removing data without being immediately noticed. Although Oracle deployed emergency protection measures, the vulnerability had already affected a significant number of organizations.
ShinyHunters' action and growing threats
The campaign was claimed by the ShinyHunters, which claims to have compromised more than 300 PeopleSoft environments across approximately 100 organizations. The group has gained a particular reputation in recent years for attacks targeting cloud services and SaaS platforms, with the primary goal of data theft and extortion through data leakage.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer

The attacks were not limited to the automotive industry. According to reports, the education, while organizational data has already been published on leak websites. The incident is yet another reminder that businesses must promptly apply available security updates, invest in threat detection mechanisms and adopt cyber resilience strategies, as attacks on critical corporate platforms become increasingly targeted and sophisticated.
Source: www.bleepingcomputer.com
