Nissan Data Breach via Oracle PeopleSoft
Analysis based on 8 articles · First reported Jun 30, 2026 · Last updated Jun 30, 2026
The data breach at Nissan, caused by a zero-day exploit in Oracle Corporation Oracle Corporation — PeopleSoft, is likely to negatively impact Nissan's stock price due to reputational damage and potential costs associated with remediation and legal liabilities. Oracle Corporation may also face scrutiny and a decline in confidence in its enterprise software security, potentially affecting its market valuation.
Nissan has disclosed a data breach affecting current and former employees in the United States, Canada, Mexico, and Brazil. The breach occurred between May 27 and June 9, 2026, when the ShinyHunters extortion group exploited CVE-2026-35273, a critical zero-day vulnerability in Oracle Corporation's Oracle Corporation — PeopleSoft software. This flaw, an unauthenticated Server-Side Request Forgery (SSRF)-to-Remote Code Execution (RCE) bug, allowed attackers to access sensitive personal data, including Social Security numbers, banking details, financial and tax information, and dependent/beneficiary records. Oracle Corporation issued an out-of-band security patch after the attacks began. Nissan has activated its incident response, engaged cybersecurity experts, secured affected systems, and is offering free credit and dark web monitoring services to affected individuals. The company has also implemented stricter payroll access controls as a precautionary measure.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard