Skip to content
Nissan Data Breach Exposes Employee Records via Oracle Vulnerability

Nissan Data Breach Exposes Employee Records via Oracle Vulnerability

First seen 29 Jun 2026, 11:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 11:56 UTC

Nissan disclosed a data breach affecting current and former employees after attackers exploited a critical vulnerability in Oracle PeopleSoft, specifically CVE-2026-35273. This breach potentially exposed sensitive information, including Social Security numbers, banking details, and payroll records, impacting employees in the U.S., Canada, Mexico, and Brazil. The ShinyHunters extortion group is believed to be behind the attack, which affected hundreds of organizations globally. Nissan activated its incident response plan, engaged cybersecurity experts, and is collaborating with Oracle to mitigate the issue. The company is offering credit and dark web monitoring services to affected individuals. As of now, Nissan has not disclosed the total number of impacted employees or the specific timeline of the breach.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Oracle disclosed a critical vulnerability in PeopleSoft with a CVSS score of 9.8, enabling unauthorized access.
Bleepingcomputer
2026-06-12
CVE-2026-35273 added to CISA KEV
The vulnerability was recognized as actively exploited, prompting emergency advisories.
Bleepingcomputer
2026-06-29
Nissan discloses data breach
Nissan informed employees about a breach involving unauthorized access to sensitive information through Oracle PeopleSoft.
Bleepingcomputer

More articles in this cluster (11)

Following this threat?

Track ShinyHunters, Nissan and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed