Nissan Americas disclosed a data breach affecting current and former employees after Oracle reported a cyber incident involving Oracle PeopleSoft software used for HR, payroll, and personnel records. Nissan said it was specifically targeted and that exposed information may include contact details, banking information, Social Security or other national identification numbers, financial and tax data, and dependent or beneficiary information. The company said the incident affected individuals in the United States, Canada, Mexico, and Brazil, and that it activated incident response procedures, engaged external cybersecurity specialists, secured affected systems, notified authorities, and planned to provide credit and dark web monitoring.
The disclosure follows Oracle’s June security update for a critical PeopleSoft Enterprise PeopleTools zero-day, tracked as CVE-2026-35273, which Oracle said was being actively exploited in the wild. The vulnerability carries a CVSS 9.8 rating and allows an unauthenticated attacker with network access over HTTP to execute arbitrary code, potentially leading to full system compromise. The overlap between Nissan’s breach notice and Oracle’s warning indicates the employee data exposure was tied to exploitation of the PeopleSoft flaw before remediation.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Nissan Americas issued an official breach notice published on the California Attorney General’s portal on 2026-06-26, stating that a cyber incident involving Oracle PeopleSoft affected current and former employees. Nissan said Oracle informed it that a cyber-event compromised PeopleSoft software used for HR, payroll, and personnel records, and that Nissan was specifically targeted.
On 2026-06-12, Oracle released a security update for Oracle PeopleSoft Enterprise PeopleTools to fix CVE-2026-35273, a critical unauthenticated remote code execution flaw. Oracle said the vulnerability was being actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.