Nissan Americas has officially confirmed that current and former employees across four countries had their personal data compromised following a targeted cyberattack exploiting a critical zero-day vulnerability in Oracle’s PeopleSoft enterprise software.
In an internal communication signed by Leon Martinez, Vice President and Chief Human Resources Officer for Nissan Americas, the automaker disclosed that threat actors gained unauthorized access to employee records managed through Oracle PeopleSoft.
The company confirmed it was “specifically targeted” in what has since been identified as a broader, multi-organization campaign.
At the core of the attack is CVE-2026-35273, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools, carrying a maximum CVSS score of 9.8.
Oracle disclosed the zero-day on June 10, 2026, releasing an emergency out-of-band patch the same day.
Nissan Confirms Data Breach
Exploitation of the flaw, which allows attackers to achieve full takeover of PeopleSoft environments without any authentication, had reportedly been ongoing since at least May 27, 2026, establishing a zero-day exploitation window of nearly two weeks.
The campaign has been attributed to ShinyHunters, a well-documented cybercrime group specializing in large-scale data theft and extortion.
By June 10, the group had compromised more than 300 PeopleSoft instances across 100+ organizations globally, according to analysis from Mandiant and Google’s Threat Intelligence Group (GTIG).
Nissan’s internal breach timeline May 27 to June 9 aligns precisely with the known ShinyHunters exploitation window.
According to the official employee notification filed with the California Attorney General on June 25, 2026, the following categories of sensitive data are believed to have been accessed:
- Contact and banking information
- Social Security Numbers (SSN) / Social Insurance Numbers (SIN) / National Identification Numbers
- Financial and tax data
- Dependent and beneficiary information
The breach is believed to affect current and former Nissan employees in the United States, Canada, Mexico, and Brazil.
Upon notification from Oracle, Nissan activated its incident response protocols and engaged external cybersecurity experts to contain and remediate the breach. Law enforcement authorities have been kept informed throughout the investigation.
As a fraud-prevention measure, Nissan now requires employees to access payroll systems, including pay stubs and direct deposit changes, only via an on-site network computer or secured VPN connection.
Nissan has also announced plans to provide free credit monitoring or dark web monitoring services to affected individuals where available and is implementing additional identity authentication layers before processing payroll changes.
Mitigations
Security researchers have identified specific mitigation steps for organizations unable to immediately patch CVE-2026-35273:
- Disable the Environment Management Hub (EMHub) Service
- Block external network access to sensitive PeopleSoft endpoints, specifically
/PSEMHUB/hub/and/PSIGW/HttpListeningConnector, at the network perimeter or firewall level - Apply Oracle’s out-of-band emergency patch released June 10, 2026
Employees and organizations are also urged to remain vigilant against follow-on phishing attempts, reset passwords on all significant accounts, and enable multi-factor authentication (MFA) across financial and email platforms.
Nissan’s exposure underscores the widening blast radius of the ShinyHunters PeopleSoft campaign, which continues to claim victims across corporate, educational, and government sectors.
Nissan has not yet disclosed the total number of affected individuals or whether the compromised PeopleSoft environment was Oracle-managed or self-hosted.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.