Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-Day (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Exploited Oracle PeopleSoft zero-day (CVE-2026-35273) by ShinyHunters
- Affected regions: US, Canada, Mexico, Brazil
- Data stolen: SSN, bank details, tax records, beneficiary info
- Nissan actions: VPN access, MFA, credit monitoring
"Nissan has disclosed that current and former employees in the US, Canada, Mexico, and Brazil had sensitive personal data stolen after attackers exploited a critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft. The breach is linked to the ShinyHunters extortion group, which targeted hundreds of organizations. Exposed data includes Social Security numbers, banking details, tax records, and beneficiary information. Nissan has restricted payroll access, is offering credit monitoring, and urges MFA."
no comments yet.