What happened
Nissan has confirmed that current and former employees across the United States, Canada, Mexico and Brazil had personal data stolen after attackers exploited a zero-day vulnerability in Oracle's PeopleSoft human resources software. In notices sent to affected individuals, the company said the exposed information includes Social Security numbers, banking details, tax records and, for some employees, national identification numbers and dependent or beneficiary information.
The theft took place between May 27 and June 9, 2026, before Oracle had a patch available, according to incident timelines published by Google-owned Mandiant, which tracked the exploitation. Nissan is one of several employers, alongside Kubota North America and Aflac's Japanese subsidiary, that disclosed related breach notifications in the days around July 3.
The vulnerability
The flaw is tracked as CVE-2026-35273, a server-side request forgery bug in the Updates Environment Management component of Oracle PeopleSoft PeopleTools, versions 8.61 and 8.62. Oracle's own security alert advisory, published June 10, 2026, rates the issue 9.8 on the CVSS scale and describes it as remotely exploitable over HTTP without authentication or user interaction, chaining into full remote code execution. Two endpoints, /PSEMHUB/hub and /PSIGW/HttpListeningConnector, are named in the advisory as the exploitation path.
Because PeopleTools underpins PeopleSoft's HR, payroll, finance and student-records modules, a successful exploit gives an attacker a direct route to exactly the kind of data Nissan says was taken.
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-35273 to its Known Exploited Vulnerabilities catalog on June 12, two days after Oracle's advisory, and set a June 15 remediation deadline for federal civilian agencies under Binding Operational Directive 26-04. CISA's KEV entry cites active exploitation as the basis for the addition, which is the agency's standard threshold rather than a judgment about who is behind it.
Who is behind it, and how that is known
Mandiant and Google's Threat Intelligence Group attributed the May 27 to June 9 exploitation window to a cluster it tracks as UNC6240, which it assesses overlaps with the group publicly known as ShinyHunters. That attribution comes from Mandiant's own incident response telemetry, not from the researchers' inference alone: ShinyHunters separately claimed the activity directly to reporters at BleepingComputer, telling the outlet it had accessed more than 300 PeopleSoft instances across upward of 100 organizations. Mandiant said it notified more than 100 organizations with internet-facing PeopleSoft systems that showed signs of compromise, and said roughly two-thirds of those were higher-education institutions. The University of Nottingham is among the confirmed victims outside the corporate sector.
Nissan's notification does not name an attacker, and the company's disclosure describes the incident only in terms of the Oracle vulnerability and the data affected.
The vendor's response
Oracle shipped an out-of-band Security Alert patch on June 10, separate from its regular quarterly Critical Patch Update cycle, which is reserved for vulnerabilities the company considers urgent enough not to wait for the next scheduled release. The advisory instructs customers running PeopleTools 8.61 and 8.62 to apply the patch immediately and notes there is no workaround short of patching.
This is the second CVSS 9.8 zero-day disclosed in an Oracle enterprise resource planning product within roughly eight months. The earlier one, CVE-2025-61882 in Oracle E-Business Suite, was exploited starting in August 2025 in a campaign linked to the Cl0p extortion group. Security researchers tracking both incidents have noted the pattern of large ERP platforms, which sit deep inside HR and finance workflows and are rarely internet-facing by design until a specific integration exposes them, becoming a recurring target for data-theft extortion rather than encryption-based ransomware.
What Nissan is offering
Nissan said it will provide free credit monitoring and dark web monitoring services to affected individuals where available, and that it has not seen evidence the exposed data has been misused. The company's notification was filed with state attorneys general as required under U.S. breach notification statutes; the number of affected individuals varies by state filing and Nissan has not published a single consolidated total.
Why it matters
The PeopleSoft campaign is a reminder that a single unauthenticated vulnerability in a widely deployed back-office platform can produce dozens of simultaneous breach disclosures with almost no direct action from any of the affected companies beyond running the software. For organizations running PeopleSoft PeopleTools 8.61 or 8.62, the patch has been available since June 10; CISA's KEV listing means the exploitation is not theoretical. Anyone still unpatched should treat this as an active incident rather than a routine update.
