ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Nissan discloses breach of personnel records through Oracle software vulnerability

Nissan has disclosed a data breach involving an Oracle PeopleSoft security flaw that compromised payroll records, banking details, Social Security numbers, and other sensitive employee information. The automaker submitted a filing to the California Attorney General on Friday, warning that it was specifically targeted in a campaign that affected hundreds of organizations using the enterprise software.


The breach is believed to have occurred between May 27 and June 9 and potentially exposed personal data including employee contact information, financial and tax records, Social Insurance numbers, national identification numbers, and dependent and beneficiary details. The incident affected current and former Nissan employees in the United States, Canada, Mexico, and Brazil.


Nissan said it activated its incident response procedures after learning of the intrusion, brought in outside cybersecurity specialists, and has been coordinating with Oracle and law enforcement. The company plans to provide affected individuals with free credit monitoring and dark web monitoring services where available.


The automaker has implemented additional security measures for its payroll systems, restricting access to employee pay slips and direct deposit changes to corporate network computers or secure VPN connections. Nissan said it will require additional identity verification before processing payroll requests and will notify employees of any confirmed exposure to their personal information.


The vulnerability, tracked as CVE-2026-35273, was exploited in a broader campaign targeting Oracle PeopleSoft users. Security researchers later confirmed that threat actors exploited the vulnerability as a zero-day flaw across more than 300 PeopleSoft instances at roughly 100 organizations, with a significant portion of attacks targeting the education sector.


The ShinyHunters extortion group claimed responsibility for the attacks and has been leaking stolen data on its website, including records from Nottingham University and the National Association of Insurance Commissioners. Nissan has not confirmed whether the incidents are connected to the ShinyHunters campaign.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543