Nissan North America disclosed that attackers exploited a critical Oracle PeopleSoft zero-day, tracked as CVE-2026-35273, to access and steal sensitive data tied to current and former employees across the United States, Canada, Mexico, and Brazil. The company’s California breach filing said the incident affected employee and former employee communications, with known breach dates of May 27, 2026 and June 9, 2026. Reporting on the incident said exposed information may include Social Security numbers, national identification numbers, banking details, tax records, and dependent or beneficiary data, prompting Nissan to restrict payroll access, add identity verification for payroll requests, and offer monitoring services where available.
The same Oracle PeopleSoft flaw was also used to breach the National Association of Insurance Commissioners (NAIC), which said an unauthorized actor gained access to part of its environment and temporarily reached certain data storage areas before publishing some of the stolen material. NAIC said the exposed data included credit rating agency information and possibly additional technical storage data, while personal information, payment data, NIPR-linked information, and several regulatory systems were not compromised. Oracle said the broader campaign affected hundreds of organizations, and public reporting linked the activity to the ShinyHunters extortion group, which has claimed more than 100 victims.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
In a June 26 update, NAIC said the intrusion was part of a broader campaign exploiting an unknown Oracle PeopleSoft vulnerability that affected multiple organizations. It also said operations had largely returned to normal, while online invoice payment via PeopleSoft remained unavailable.
Nissan North America submitted breach-notification materials dated June 25, 2026, concerning a cybersecurity incident affecting employee and former employee communications. The filing listed the known breach dates as May 27 and June 9, 2026.
NAIC publicly disclosed the incident on June 17, confirming that an attacker had accessed part of its environment and that some accessed data was later published. It said several categories of personal, payment, and regulatory system data were not compromised.
NAIC said it detected a security breach on June 11 after an unauthorized actor accessed part of its environment by exploiting a zero-day vulnerability in Oracle PeopleSoft. The organization said it then contained the breach and blocked the attacker’s access.
Nissan's filing identified June 9, 2026, as the end of the breach window for the employee-related cybersecurity incident. The company said current and former staff in the United States, Canada, Mexico, and Brazil may have had sensitive personal data exposed.
Nissan North America listed May 27, 2026, as the start of a cybersecurity incident affecting current and former employee communications and later linked the intrusion to exploitation of Oracle PeopleSoft.
Nissan disclosed that attackers exploited Oracle PeopleSoft zero-day CVE-2026-35273 to steal sensitive personal data from current and former employees. The company said it secured systems, coordinated with Oracle, restricted payroll access, added identity checks, and would offer monitoring services where available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourceoag.ca.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.