# Nissan Hit in Massive Oracle PeopleSoft Zero-Day Campaign Targeting Fortune 500 Employee Data
The automotive giant becomes the latest major corporation to fall victim to widespread exploitation of a critical Oracle PeopleSoft vulnerability, marking a dangerous escalation as sophisticated extortion gangs move beyond education institutions to enterprise HR systems managing millions of records.
## The Threat
Nissan has disclosed a significant data breach affecting current and former employees across its Americas operations after threat actors exploited a zero-day vulnerability in Oracle PeopleSoft to infiltrate the company's HR infrastructure. The breach, linked to the ShinyHunters extortion gang, exposed sensitive employee records including names, contact information, banking details, Social Security numbers, Social Insurance numbers, national identification numbers, tax documents, and dependent/beneficiary information from employees in the United States, Canada, Mexico, and Brazil.
The vulnerability at the center of this campaign—CVE-2026-35273 in Oracle PeopleSoft PeopleTools—was exploited as an unpatched zero-day between May 27 and June 9, 2026. According to Mandiant's investigation, threat actors weaponized the flaw to compromise over 300 PeopleSoft instances across approximately 100 organizations. While initial exploitation primarily targeted the education sector (affecting institutions like Nottingham University), the breach now extends into enterprise corporations, demonstrating that attackers are systematizing their approach to high-value targets managing employee payroll and personnel records.
ShinyHunters, a sophisticated extortion collective with a documented history of targeting Salesforce, Snowflake, and SaaS platforms, has already begun leaking stolen datasets on its public data leak site. The group's pivot from cloud collaboration platforms to on-premises HR systems signals an expanding threat model for defenders—HR and payroll databases remain lucrative targets precisely because they contain the comprehensive personal and financial information needed for identity theft, tax fraud, and social engineering campaigns.
## Severity and Impact
| Attribute | Details |
|-----------|---------|
| CVE ID | CVE-2026-35273 |
| Product | Oracle PeopleSoft PeopleTools |
| CVSS Score | 9.8 (Critical) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| CWE | CWE-284 (Improper Access Control) |
| Exploitation Timeline | Active zero-day exploitation, May 27–June 9, 2026 |
| Confirmed Victims | 100+ organizations, 300+ instances |
## Affected Products
Oracle PeopleSoft:
Impacted Organizations (Confirmed):
Geographic Impact:
Employee data compromised in the following regions:
## Mitigations
Immediate Actions for Organizations:
1. Apply Oracle Patches: Deploy Oracle's emergency security patches for CVE-2026-35273 immediately. Oracle has released fixes; confirm your PeopleTools version is fully patched.
2. Audit Access Logs: Review PeopleTools access logs from May 27 through June 9, 2026, and continuing through the present to identify unauthorized access patterns or data exfiltration indicators.
3. Network Segmentation: Isolate PeopleTools instances from direct internet exposure. Require VPN or authorized network access for all HR system connections.
4. Monitor for Indicators of Compromise: Watch for unusual outbound traffic, large data transfers, or access from unexpected geographies. Monitor for command-and-control communications.
5. Credential Rotation: Reset passwords for all administrative and service accounts with PeopleTools access. Enforce multi-factor authentication for HR system access.
6. Notification and Remediation: Following Nissan's lead, notify affected employees of potential compromise and offer credit monitoring and dark web monitoring services where feasible.
7. Enhanced Identity Verification: Implement additional verification steps before processing payroll changes, direct deposit modifications, or sensitive employee record updates to prevent follow-on fraud.
8. Third-Party Risk Review: Assess integration partners and third-party vendors with PeopleTools API access; verify they have not been compromised as secondary entry points.
## References
---
## HackWire Analysis
This breach represents a critical inflection point in enterprise cybersecurity: the zero-day exploit landscape is no longer confined to cloud SaaS platforms. ShinyHunters' shift from targeting Salesforce and Snowflake to systematically exploiting Oracle's on-premises HR infrastructure shows a maturing extortion operation that understands where the highest-value data sits—not in collaborative tools, but in centralized HR systems managing the complete identity, financial, and tax footprints of hundreds of thousands of workers.
The timeline is instructive and troubling. Threat actors actively exploited this vulnerability for a two-week window (May 27–June 9) before Mandiant detected it and Oracle released patches. That gap created a window where over 100 organizations were compromised before they even knew the flaw existed. Nissan's breach disclosure months after the initial campaign ended suggests that many victims are still in investigation phases, meaning the true scope of employee data exposure may not be fully understood for weeks or months.
The data harvested here—SSNs, tax IDs, banking information, dependent records—is far more valuable to criminal syndicates than email addresses or employee directories. This data feeds identity theft pipelines, synthetic fraud rings, and tax fraud schemes. Nissan's decision to restrict payroll changes to VPN-only access is defensive, but it's also a signal that the company is now operating under the assumption that attackers have the keys to the kingdom and will attempt follow-on fraud.
For defenders, this incident underscores three critical lessons: (1) on-premises legacy systems are still zero-day targets despite the cloud migration narrative; (2) extortion gangs are graduating from spray-and-pray attacks to systematic campaigns against high-value targets; (3) HR and payroll data is now a first-class target alongside customer databases and intellectual property. Organizations running PeopleSoft, Workday, or similar HR platforms should treat emergency patching as a critical incident, not a routine maintenance window.
— HackWire Editorial
---
## Related Coverage