Theregister Nissan Data Breach Exposes Employee Records via Oracle Vulnerability
Article Content
- •Nissan's data breach affects current and former employees across multiple countries.
- •The breach is linked to CVE-2026-35273, a critical vulnerability in Oracle PeopleSoft.
- •ShinyHunters extortion group is believed to be responsible for the attack.
Nissan disclosed a data breach affecting current and former employees after attackers exploited a critical vulnerability in Oracle PeopleSoft, specifically CVE-2026-35273. This breach potentially exposed sensitive information, including Social Security numbers, banking details, and payroll records, impacting employees in the U.S., Canada, Mexico, and Brazil. The ShinyHunters extortion group is believed to be behind the attack, which affected hundreds of organizations globally. Nissan activated its incident response plan, engaged cybersecurity experts, and is collaborating with Oracle to mitigate the issue. The company is offering credit and dark web monitoring services to affected individuals. As of now, Nissan has not disclosed the total number of impacted employees or the specific timeline of the breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (11)
Following this threat?
Track ShinyHunters, Nissan and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Hack Exposes Sensitive FBI Employee Data On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security…
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…