June 30, 2026: Nissan Americas confirmed it was breached through Oracle PeopleSoft zero-day CVE-2026-35273 in the ShinyHunters/UNC6240 campaign that compromised 300+ PeopleSoft instances worldwide—exposing sensitive employee HR data across the United States, Canada, Mexico, and Brazil.
What happened
Per BleepingComputer and a California Attorney General filing, unauthorized access occurred May 27 through June 9, 2026—more than two weeks before Oracle's June 10 emergency patch. Mandiant and Google GTIG attribute the broader campaign to financially motivated group UNC6240 (ShinyHunters).
What data was exposed
Nissan's notification states potentially exposed categories include:
- Social Security Numbers, Social Insurance Numbers, and national identification numbers
- Contact information
- Tax and financial information
- Banking details
- Dependents and beneficiaries information
The breach affects current and former employees in four countries. Nissan has not yet attested a total employee count.
Nissan's response
Nissan activated incident response, engaged external cybersecurity specialists, and cooperated with law enforcement. Containment measures include restricting payroll portal functions—pay slip viewing and direct deposit changes—to corporate network computers or secure VPN with additional identity authentication. Nissan is arranging free credit and dark-web monitoring where available.
PeopleSoft campaign context
Nissan joins victims including the NAIC, universities, and other enterprises in the June 2026 ShinyHunters wave exploiting unauthenticated SSRF-to-RCE in PeopleTools 8.61/8.62. Post-exploitation indicators include MeshCentral agents disguised as Azure services and ransom notes named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.
Action items for affected employees
- Freeze credit at Equifax, Experian, and TransUnion (US) or equivalent bureaus in Canada, Mexico, and Brazil.
- Enroll in Nissan's monitoring when notification letters arrive.
- Watch for W-2 and payroll phishing citing real SSN fragments or employer details.
- Rotate banking credentials if direct-deposit details were on file.
Canonical record: Nissan PeopleSoft ShinyHunters 2026 on BreachHistory (distinct from nissan2026 Everest vendor incident).