All stories

Nissan Employee Data Breach Exposes Sensitive Info via Oracle Zero-Day Exploit

Nissan has disclosed a data breach affecting current and former employees due to an Oracle PeopleSoft vulnerability exploited by ShinyHunters, leading to unauthorized access of sensitive personal information. The attack highlights the critical need for organizations using PeopleSoft to immediately implement Oracle's emergency mitigations. Defenders should prioritize securing their systems against similar zero-day vulnerabilities.

Summary

Nissan has reported a significant data breach impacting its employees in North America and Latin America after threat actors exploited an unpatched vulnerability in Oracle PeopleSoft software. The attackers, identified as ShinyHunters, leveraged this flaw to access sensitive employee data, including Social Security numbers and banking information. This incident underscores the urgency for organizations using Oracle's PeopleSoft to apply emergency patches and bolster their security measures against similar threats.

What Happened

Nissan disclosed that it suffered a data breach affecting both current and former employees across North America and Latin America. The breach was linked to an exploitation of an unpatched zero-day vulnerability in Oracle PeopleSoft software, used by Nissan for managing employee information such as payroll and tax administration. ShinyHunters, a known extortion group, claimed responsibility for the attacks, which involved data theft from hundreds of organizations.

Technical Details

The breach was facilitated through a critical remote code execution vulnerability in Oracle PeopleSoft's Environment Management component, identified as CVE-2026-35273. This zero-day exploit allowed attackers to gain unauthorized access to sensitive systems and data. Mandiant confirmed the exploitation of this vulnerability between May 27 and June 9, 2026, before Oracle released emergency mitigations on June 10, 2026.

Affected Products and Fixed Versions

The primary software affected by this breach is Oracle PeopleSoft. Organizations using this platform are advised to apply Oracle's emergency mitigations immediately to protect against similar attacks. While specific fixed versions were not detailed in the sources, applying the latest security patches from Oracle is crucial.

Exploitation Status

ShinyHunters exploited CVE-2026-35273 as a zero-day vulnerability before Oracle publicly acknowledged it and released patches. This exploitation underscores the importance of timely patch management and threat intelligence to defend against emerging threats.

Indicators of Compromise

While specific indicators of compromise (IOCs) were not detailed in the sources, organizations should monitor for unusual administrative activities and unauthorized access attempts on their PeopleSoft systems. Engaging with Oracle's security advisories and applying recommended mitigations are key steps in identifying and responding to potential breaches.

Detection Opportunities

Organizations can enhance their detection capabilities by monitoring network traffic for anomalies related to known ShinyHunters tactics, techniques, and procedures (TTPs). Implementing breach and attack simulation tools can also help identify vulnerabilities before attackers do, allowing for proactive defense measures.

Timeline

  • May 27 - June 9, 2026: Active exploitation of CVE-2026-35273 by ShinyHunters.
  • June 10, 2026: Oracle releases emergency mitigations for the PeopleSoft vulnerability.

Why This Matters for Defenders

This incident highlights the critical importance of timely patch management and the need for organizations to stay informed about emerging threats. By understanding how attackers exploit vulnerabilities in widely used software like Oracle PeopleSoft, defenders can better prepare their systems against similar attacks.

What Remains Unclear

The full extent of the data accessed by attackers during the Nissan breach remains unclear. Additionally, while ShinyHunters claimed responsibility for the attack, further details on their specific methods and objectives are not fully disclosed in the sources.

Defender Guidance

Organizations using Oracle PeopleSoft should immediately apply the emergency mitigations released by Oracle to protect against CVE-2026-35273. Regularly updating software with the latest security patches and monitoring systems for unusual activities can significantly reduce the risk of similar breaches. Engaging with cybersecurity experts to conduct vulnerability assessments and penetration testing is also recommended to identify and address potential weaknesses in an organization's security posture.

Sources

  1. https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
  2. https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -