Nissan has confirmed a data breach affecting current and former employees across the U.S., Canada, Mexico, and Brazil after attackers exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft, the enterprise platform Nissan uses for payroll and HR management. The unauthorized access occurred between May 27 and June 9, 2026, and is attributed to the ShinyHunters extortion group, which has reportedly leveraged the same flaw to compromise hundreds of organizations running PeopleSoft for HR operations.
Compromised data may include contact details, banking information, Social Security and national ID numbers, tax records, and dependent/beneficiary data. Nissan has engaged external cybersecurity experts, notified affected employees, and is offering credit monitoring and dark web monitoring services. The company has also implemented stricter payroll access controls, requiring additional identity verification and restricting access to company networks or secure VPNs.
Source
BleepingComputer · SecurityWeek · Infosecurity Magazine
Commentary
ShinyHunters weaponizing an Oracle PeopleSoft zero-day is a significant escalation for a group historically known for web application compromises and credential theft. The fact that “hundreds of organizations” may be affected turns this from a Nissan story into an enterprise HR platform supply chain story. Any organization running PeopleSoft for payroll should be treating CVE-2026-35273 as a hair-on-fire priority.
The broader pattern here is alarming: enterprise middleware — PeopleSoft, MOVEit, SAP — continues to be a high-value, low-visibility target. These platforms sit behind the firewall, manage the most sensitive employee data, and often run on patch cycles measured in quarters rather than days. Nissan’s post-breach response of restricting payroll access to VPN-only is a reasonable containment measure, but the real question is why a zero-day in PeopleSoft could grant access to this scope of data without triggering anomaly detection during a two-week dwell time.
