2026 Nissan Americas — Oracle PeopleSoft zero-day (CVE-2026-35273); ShinyHunters employee HR breach
Data compromised
Current and former employee HR data in US, Canada, Mexico, and Brazil: names, contact details, SSN/SIN/national IDs, tax and financial information, banking details, dependents and beneficiaries—employee count not yet attested
Technical writeup
Verified breach — disclosed June 30, 2026. Nissan Americas confirmed via California Attorney General notification and trade press that threat actors exploited Oracle PeopleSoft zero-day CVE-2026-35273 (CVSS 9.8, patched June 10, 2026) in the broader ShinyHunters/UNC6240 campaign Mandiant and Google GTIG track. Unauthorized access occurred May 27 through June 9, 2026—before Oracle's out-of-band advisory. Potentially exposed employee data includes Social Security Numbers, Social Insurance Numbers, national identification numbers, contact information, tax and financial records, banking details, and dependents/beneficiaries information for current and former employees in the United States, Canada, Mexico, and Brazil. Nissan activated incident response, engaged external specialists, restricted payroll portal functions (pay slips, direct deposit changes) to corporate network/VPN with added authentication, and is arranging credit and dark-web monitoring where available. Distinct from nissan2026 (Everest third-party dealership vendor incident). BreachHistory indexes recordsAffected 0 pending attested employee counts.
Root cause
Unauthorized access via Oracle PeopleSoft zero-day CVE-2026-35273 exploited in ShinyHunters/UNC6240 campaign, May 27–June 9, 2026
References
- https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
- https://cybersecuritynews.com/nissan-confirms-data-breach/
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625558
- https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/