# Nissan Hit in Widespread Oracle PeopleSoft Zero-Day Campaign: Employee Data Exposed Across Americas


Automotive manufacturer becomes confirmed victim of ShinyHunters' exploitation of CVE-2026-35273, joining 100+ targeted organizations in broad supply chain assault


Nissan Americas has confirmed it fell victim to a sophisticated zero-day exploitation campaign targeting Oracle PeopleSoft, a widely-deployed human capital management platform used by enterprises globally to manage payroll, tax administration, and employee records. The breach, disclosed in a filing with the California Attorney General, marks the latest major corporation to be compromised through the same vulnerability currently weaponized by the ShinyHunters extortion group.


According to Nissan's breach notification, attackers exploited CVE-2026-35273 to gain unauthorized access to employee information spanning four countries: the United States, Canada, Mexico, and Brazil. The compromised data includes highly sensitive personally identifiable information (PII) and financial details—specifically Social Security numbers, banking account information, and tax and financial records for both current and former employees.


The carmaker's security team is still conducting its investigation, and a definitive scope of the breach remains unclear. However, Nissan acknowledged that the ShinyHunters group is believed to be responsible for the intrusion. As of publication, Nissan has not been publicly listed on ShinyHunters' extortion website, leaving open questions about whether the group intends to demand ransom or has already monetized the stolen data through other channels.


## The Campaign Scope: A Supply Chain Crisis Unfolding


The PeopleSoft zero-day campaign represents a significant escalation in the threat landscape—not just in technical sophistication but in targeting breadth. ShinyHunters allegedly compromised more than 100 organizations using the affected Oracle platform, though public confirmations remain limited, obscuring the full scale of the incident.


Confirmed victims currently include:


  • Nissan Americas – Automotive manufacturer
  • University of Nottingham – UK-based research university
  • National Association of Insurance Commissioners (NAIC) – US insurance regulatory body
  • Illinois Central College – Community college in Illinois
  • Moody Bible Institute – Chicago-based educational institution

  • Notably, the education sector appears disproportionately impacted, raising concerns about whether threat actors deliberately prioritized institutions with limited cybersecurity resources or whether educational organizations simply represent a larger share of PeopleSoft deployments.


    ## Technical Details: CVE-2026-35273 and Attack Methodology


    CVE-2026-35273 represents a zero-day vulnerability in Oracle PeopleSoft—meaning the flaw was unknown to Oracle and remained unpatched at the time of active exploitation. The specific technical vector has not been fully disclosed publicly, a common practice during active exploit campaigns to prevent mass exploitation by less sophisticated threat actors.


    However, based on industry patterns with PeopleSoft breaches:


  • Initial Access: Attackers likely exploited the vulnerability to bypass authentication or gain unauthenticated access to the PeopleSoft instance
  • Lateral Movement: Once inside, threat actors escalated privileges to access the employee database backend
  • Data Exfiltration: Target systems store centralized employee records including tax ID numbers, direct deposit banking details, and sensitive HR documentation
  • Dwell Time: The campaign timeline remains unclear, but organizations typically discover PeopleSoft breaches weeks or months after initial compromise

  • The use of a zero-day in this campaign suggests a moderately sophisticated adversary—one with access to exploit development resources but not necessarily nation-state-level capabilities. ShinyHunters' prior operations have focused on extortion and data theft rather than espionage, consistent with a financially-motivated criminal group.


    ## Nissan's Exposure: A Repeat Targeting Pattern


    This breach represents the second major security incident affecting Nissan in six months. In April 2026, the Everest ransomware group claimed to have stolen customer data from the automotive manufacturer, though details of that intrusion remain limited. The repeated targeting suggests Nissan may face structural vulnerabilities in its cybersecurity posture—or represents a high-value target that threat groups actively pursue due to the valuable data (customer, employee, supplier) housed in its systems.


    For Nissan's affected employees across four countries, the implications are severe:


    | Data Type | Risk | Remediation |

    |---|---|---|

    | Social Security Numbers | Identity theft, fraud, tax fraud | Credit monitoring, fraud alerts |

    | Banking Information | Direct account compromise, wire fraud | Account freezes, transaction monitoring |

    | Tax/Financial Records | Filing fraud, refund theft | IRS fraud alerts, tax return monitoring |


    Nissan has not yet announced whether it will offer complimentary credit monitoring or identity theft protection—a common remediation step, though one that offers limited protection against determined financial fraud.


    ## Implications for Enterprises and Supply Chains


    The PeopleSoft campaign exposes a critical vulnerability in enterprise software deployment and vulnerability management. Several patterns emerge:


    1. Centralized HR Systems as Crown Jewels

    PeopleSoft instances house some of the most sensitive corporate data—employee identities, compensation, tax information, and banking details. A single compromised system can expose employee bases in the thousands or tens of thousands.


    2. Zero-Day Persistence in Legacy Systems

    PeopleSoft is a mature, widely-deployed platform with a large attack surface. Oracle's patching cadence may not align with the speed at which sophisticated threat actors discover and weaponize vulnerabilities.


    3. Supply Chain Targeting

    Threat actors appear to be systematically scanning for unpatched PeopleSoft instances, suggesting the vulnerability either has obvious indicators of compromise or is easily detectable via network reconnaissance.


    4. Extortion vs. Data Monetization

    The fact that some victims (like Nissan) haven't appeared on ShinyHunters' public site raises questions about negotiation, delisting fees, or alternative data sale channels—potentially indicating a black market for employee financial records.


    ## Recommendations for Organizations


    For PeopleSoft Administrators:


  • Immediate: Audit PeopleSoft access logs for anomalous queries, particularly those targeting the employee, compensation, or benefits tables
  • This Week: Apply all available Oracle security patches and test in a staging environment before production deployment
  • Network Segmentation: Isolate PeopleSoft instances from general corporate networks; restrict database access by IP whitelist
  • Threat Hunting: Engage incident response teams to sweep for indicators of compromise aligned with this campaign's IOCs (when disclosed)

  • For Affected Employees:


  • Monitor financial accounts and credit reports
  • Place fraud alerts with credit bureaus
  • File preemptively with the IRS if concerned about tax fraud
  • Document any unauthorized charges or credit inquiries

  • For Regulators and Insurers:


    This incident underscores the need for enhanced scrutiny of critical HR systems as part of cybersecurity frameworks and cyber insurance underwriting.


    ---


    ## HackWire Analysis


    The PeopleSoft campaign represents a shift in how threat actors are targeting multinational enterprises: not through perimeter breaches or phishing campaigns, but through deliberate zero-day exploitation of trusted, mission-critical platforms. The fact that ShinyHunters has managed to compromise 100+ organizations suggests either that CVE-2026-35273 is trivial to exploit and detect, or that many enterprises lack the monitoring and patch management discipline to respond in time.


    What's particularly striking is the *visibility gap*. We know of perhaps five confirmed victims, yet the group claims 100+. This tells us that many compromised organizations either haven't discovered the breach yet, are handling it quietly, or never will—having no detection mechanisms for lateral movement within PeopleSoft. For a system that sits at the center of payroll and employee identity management, this is a critical failure point.


    The targeting of institutions like NAIC and educational centers suggests ShinyHunters may be pursuing a "diverse portfolio" strategy—hitting high-profile victims (like Nissan) to establish credibility and media attention, while quietly extracting value from less-visible organizations that might not generate headlines and thus may be more amenable to payment. The absence of Nissan from their public victim list could indicate negotiation in progress, a delisting fee, or a decision to monetize the data through private channels.


    The broader signal: zero-day campaigns are moving upstream to software vendors used by enterprises, not just individual targets. PeopleSoft, SAP, ServiceNow—these are the next frontier. Organizations that rely on centralized HR platforms need to assume they will eventually be targeted and build resilience, segmentation, and detection accordingly. — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)