Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

12792

Nissan Data Breach After Oracle PeopleSoft Attacks Highlights Critical Business Application Risk

Overview

Nissan Americas confirmed a data breach affecting current and former employees following attacks against an Oracle PeopleSoft environment. The incident is part of a broader campaign involving a critical Oracle PeopleSoft PeopleTools vulnerability tracked as CVE-2026-35273.

The vulnerability affects the Updates Environment Management component in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. It allows an unauthenticated attacker with network access over HTTP to compromise a PeopleSoft environment and, if successfully exploited, achieve Remote Code Execution (RCE).

The case matters because PeopleSoft is not a peripheral application. In many organizations, systems like this process HR, payroll, financial, and employee data. When such a platform is compromised, the risk affects data, processes, payments, access, and regulatory obligations.

What Happened

Oracle published an out-of-band security alert for CVE-2026-35273 on June 10, 2026. The vulnerability is critical because it can be exploited without credentials or user interaction.

Google Threat Intelligence Group and Mandiant linked the active campaign to UNC6240, also known as ShinyHunters. Their analysis states that the activity was observed between May 27 and June 9, 2026, before Oracle published its advisory. This means the vulnerability was exploited as a zero-day.

In breach notifications to affected individuals, Nissan Americas stated that the incident was connected to the Oracle PeopleSoft vulnerability and affected current and former employees in multiple countries. Public reporting indicates that potentially affected data includes contact information, banking information, national identification numbers, tax and financial information, and dependent or beneficiary information.

Why Oracle PeopleSoft Is a High-Value Target

ERP and HR platforms are attractive to attackers because they concentrate sensitive information and business processes in one place. PeopleSoft environments often contain:

  • employee profiles;
  • payroll data;
  • bank account details;
  • tax information;
  • national identification numbers;
  • dependent information;
  • internal HR processes;
  • integrations with other enterprise systems.

A compromised PeopleSoft environment can give attackers access to data that is valuable for extortion, fraud, follow-on phishing, and identity abuse.

How the Attack Works

CVE-2026-35273 is described as a vulnerability in the Updates Environment Management component of PeopleSoft PeopleTools. Under specific conditions, an attacker with network reach to a vulnerable instance can exploit the issue without authentication.

Public technical analysis describes the chain as a combination of Server-Side Request Forgery (SSRF) and Remote Code Execution (RCE). In practical terms, this means an attacker can cause the server to make requests or perform actions on their behalf and then reach code execution in the affected environment.

After initial exploitation, public reports describe additional activity, including:

  • PeopleSoft configuration reconnaissance;
  • deployment of remote management tooling;
  • movement toward internal systems;
  • data collection and compression;
  • exfiltration;
  • placement of extortion notes.

This pattern shows that the attack does not end with exploitation. It starts there.

Potential Impact

In Nissan’s case, publicly listed affected categories include employee and HR-related data. This increases the risk of follow-on abuse because this type of information can support targeted attacks.

Potential consequences include:

  • theft of personal and financial information;
  • payroll or bank change fraud;
  • phishing against current and former employees;
  • misuse of dependent and beneficiary data;
  • extortion through data exposure;
  • regulatory notification obligations;
  • additional reviews of HR, payroll, and identity processes.

For organizations running PeopleSoft, the key question is not only whether the patch has been applied. It is whether access occurred before the patch was available and whether there are signs of activity after initial exploitation.

Recommended Actions

Organizations using Oracle PeopleSoft PeopleTools 8.61 or 8.62 should treat CVE-2026-35273 as a priority risk.

Priority actions include:

  • apply the security update or mitigation measures published by Oracle;
  • check whether PeopleSoft instances were exposed to the internet;
  • restrict external access to sensitive PeopleSoft endpoints;
  • review logs for activity before and after June 10, 2026;
  • hunt for unusual requests to PSEMHUB and PSIGW components;
  • check for unknown remote management agents or new services;
  • analyze outbound traffic from PeopleSoft servers;
  • rotate credentials that may have been accessible from a potentially compromised environment;
  • review HR, payroll, and identity integrations;
  • assess affected data and regulatory obligations.

Patching is only the first step. If exploitation began before the advisory, the organization must check for compromise that may already have occurred.

DIAMATIX Perspective

This incident shows why critical business applications should be monitored as part of security operations, not only managed as enterprise IT assets.

ERP, HR, and payroll systems do not always appear as classic attack surface topics. In practice, they are among the most valuable targets. They contain data that can lead to financial fraud, identity abuse, regulatory impact, and pressure on the organization.

Protection requires more than a standard patch process. Organizations need:

  • an inventory of critical business applications;
  • control over external exposure;
  • application log monitoring;
  • connection between vulnerability management and SOC analysis;
  • incident response readiness when exploitation predates patching;
  • review of the data and processes served by the platform.

When a business application with access to employee and financial data is compromised, response must bring together IT, security, HR, legal, finance, and management.

CISO Analysis

From a CISO perspective, the Nissan and Oracle PeopleSoft case is a critical business platform risk.

Key questions include:

  • Do we have a full list of PeopleSoft and other ERP or HR systems?
  • Which of them are exposed to the internet or partner networks?
  • How quickly can we apply an emergency patch to a critical business system?
  • Do we check for exploitation before patching, or only close the vulnerability?
  • Does the SOC have logs and visibility from the PeopleSoft environment?
  • Do we know which credentials and integrations were accessible through the platform?
  • Do we have a communication plan for employees if HR or payroll data is breached?

This type of attack shows that vulnerability management must be tied to business context. A vulnerability in a system holding payroll and employee data carries a different level of risk than a vulnerability in an isolated environment.

What This Means for Your Environment

  • This type of risk relies on a critical business platform with access to sensitive data, identities, and internal processes.
  • Detection depends on visibility into application logs, network access, outbound traffic, new services, remote management tooling, and unusual requests.
  • Response requires patching, compromise assessment, credential rotation, data impact analysis, and coordination between security, IT, and business teams.

Do you know which ERP, HR, and payroll systems in your environment are externally reachable?

Can you prove whether a critical vulnerability was exploited before the patch was applied?

See how risks in critical business applications are investigated and handled in real operational environments.

Contact DIAMATIX
Trusted · Innovative · Vigilant


Sources

  • Oracle Security Alert Advisory for CVE-2026-35273.
  • NVD. CVE-2026-35273 vulnerability record.
  • Google Cloud / Mandiant. ShinyHunters targets Oracle PeopleSoft application infrastructure.
  • BleepingComputer. Nissan employee data breach linked to Oracle zero-day attacks.
  • Rapid7. Active exploitation of Oracle PeopleSoft zero-day CVE-2026-35273.

This article is based on publicly available technical information and analysis as of June 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.