1. Executive summary
Nissan has disclosed a data breach affecting current and former employees across the US, Canada, Mexico, and Brazil, linked to the widespread exploitation of CVE-2026-35273 — a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools. The breach, occurring between May 27 and June 9, 2026, resulted in the theft of sensitive employee data including payroll records, banking information, Social Security numbers, and tax records. Attribution to the ShinyHunters extortion group is claimed by the group itself and reported by multiple outlets, but ShinyHunters has no MITRE ATT&CK profile in the verified reference data — treat attribution as unconfirmed. EMEA financial services running Oracle PeopleSoft instances are at direct risk; Oracle has released a patch and emergency mitigations.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17: ICT-related incident management process | Nissan activated incident response, engaged external cybersecurity experts, and secured affected systems following the breach. | Financial institutions running PeopleSoft must have an equivalent incident management process ready; if a comparable breach occurs, it must be invoked immediately. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | Nissan filed breach notifications with the California Attorney General's Office; the breach affects personnel records across multiple jurisdictions. | If a financial institution's PeopleSoft instance is compromised, the incident may meet the threshold for reporting to competent authorities under DORA. |
| DORA Art. 28: ICT third-party risk — general principles | The breach originates from a vulnerability in Oracle (a third-party ICT provider) PeopleSoft, with Oracle informing Nissan of the cyber event. | Financial institutions must assess their third-party risk exposure to Oracle PeopleSoft as an ICT third-party provider. |
| NIS2 Art. 21(2)(d): supply chain security measures | The vulnerability is in Oracle PeopleSoft, a third-party software component in the supply chain. | NIS2-covered entities must ensure supply chain security measures cover third-party enterprise software like PeopleSoft, including patch management and vulnerability monitoring. |
| NIS2 Art. 23: incident reporting obligations | A significant incident involving exploitation of a critical vulnerability with data exfiltration affecting multiple organizations. | NIS2-covered entities that experience a comparable breach must report the incident to their CSIRT/competent authority within the required timeframe. |
3. Technical analysis & attack chain
Confirmed attack chain
- Initial access — Threat actors exploited CVE-2026-35273, a CVSS 9.8 critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools. The flaw allows remote, unauthenticated attackers with network access via HTTP to compromise the platform and achieve full takeover. The vulnerability permits unauthenticated remote code execution.
- Scope of exploitation — Over 300 PeopleSoft instances across 100+ organizations were breached. Mandiant confirmed exploitation occurred between May 27 and June 9, 2026. Over two-thirds of affected organizations were in the higher education sector, but corporate victims including Nissan and the National Association of Insurance Commissioners (NAIC) were also targeted.
- Data access and exfiltration — At the University of Nottingham, ShinyHunters claimed to have stolen 40 GB of personal data and billing records belonging to hundreds of thousands of current and former students. In Nissan's case, accessed data may include: employee contact information, banking information, Social Security numbers, Social Insurance numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary details.
- Extortion — Stolen data was published on ShinyHunters' data leak site when victims refused to pay extortion demands. The University of Nottingham's data was posted on the leak site on a Tuesday and the stolen files were published later that same day. NAIC data was also leaked.
- Post-incident containment (Nissan) — Nissan restricted access to employee pay slips and direct deposit changes to company network computers or secured VPN connections only, and implemented additional identity verification measures before processing payroll requests. Nissan engaged external cybersecurity experts, secured affected systems, and is working with Oracle.
Patch and mitigation status
Oracle disclosed CVE-2026-35273 and released emergency mitigations. SecurityWeek reports Oracle has released a patch for CVE-2026-35273. Oracle has not publicly confirmed that the flaw was exploited in the wild. Mandiant CTO Charles Carmakal stated "Oracle released mitigations" and "Patches should come soon" in a LinkedIn post — note this statement predates the SecurityWeek report of a patch release, creating a timeline discrepancy; the current state per SecurityWeek is that a patch is available.
Confidence caveats
- Attribution to ShinyHunters is unconfirmed. The group has no MITRE ATT&CK profile in the verified reference data. Attribution rests on ShinyHunters' own claims to BleepingComputer and The Register, and on reporting that links the Nissan breach timeline to the broader campaign. Nissan has not confirmed the connection, though its California filing lists the breach period as May 27 through June 9, broadly aligning with the reported exploitation timeline.
- Whether the compromised PeopleSoft environment was hosted by Oracle or by Nissan itself is unclear — The Register notes the employee FAQ "offers no clue as to what the vulnerability is, whether Oracle has patched it, or whether the compromised PeopleSoft environment was hosted by Oracle or by Nissan itself."
- The specific vulnerability exploited in the Nissan breach is not confirmed by Nissan. Nissan's filing attributes the incident to "an unknown vulnerability in Oracle's PeopleSoft software." The link to CVE-2026-35273 is inferred from the timeline overlap and the broader campaign context, not directly confirmed by Nissan.
4. Mitigation & containment
P1 — Within 24 hours
- Identify all Oracle PeopleSoft instances in your estate, including those hosted by third parties or in Oracle Cloud. Inventory versions of PeopleSoft Enterprise PeopleTools.
- Check for exposure: Verify whether any PeopleSoft instances are internet-accessible via HTTP. If remote access is not required, restrict access at the network/firewall level immediately — block inbound HTTP/HTTPS to PeopleSoft servers from untrusted networks.
- Apply Oracle's emergency mitigations for CVE-2026-35273 if the patch has not yet been deployed. Follow Oracle's security alert instructions.
- Review access logs for the period May 27 – June 9, 2026 for signs of unauthenticated access, anomalous HTTP requests, or unexpected data export activity from PeopleSoft servers.
P2 — Within 72 hours
- Apply the Oracle patch for CVE-2026-35273 to all PeopleSoft instances. SecurityWeek reports the patch is available. Verify patch deployment across all instances.
- Restrict administrative access to PeopleSoft to internal corporate network or VPN only, following Nissan's model — pay slips, direct deposit changes, and payroll processing should require additional identity verification.
- Audit PeopleSoft user accounts and sessions for the breach window — look for newly created accounts, privilege escalations, or unusual data access patterns (bulk HR/payroll record access).
- Engage your incident response team and third-party forensic specialists if any indicators of compromise are found. Notify Oracle support.
P3 — Within 7 days
- Conduct a full vulnerability assessment of all PeopleSoft components, including PeopleTools, against current Oracle security advisories.
- Review third-party risk arrangements with Oracle — confirm whether Oracle-managed PeopleSoft environments are included in your vendor risk assessments and contractual security provisions (DORA Art. 28/30).
- Implement network segmentation to limit blast radius — PeopleSoft servers should not have unrestricted access to HR data stores, file shares, or identity infrastructure.
- Prepare breach notification templates for affected individuals and regulators, given the multi-j jurisdictional impact pattern (Nissan affected employees in US, Canada, Mexico, and Brazil).
- Monitor ShinyHunters' data leak site for any organisational data. Engance dark web monitoring services for your organisation's domains and data.
5. Indicators of compromise
No indicators of compromise (IP addresses, domains, file hashes, specific user agents, or exact exploit payloads) are available in the source material. The sources describe the campaign and its impact but do not publish technical IOCs such as attacker infrastructure, malware samples, or exploit artefacts.
6. Detection
Insufficient indicators to author detection rules.
The sources do not contain specific IOCs (IP addresses, domains, file hashes, user agents, exploit payloads, mutex names, registry keys, or distinctive strings) that would enable reliable YARA or Sigma rule authorship. Defenders should focus on behavioural detection: anomalous unauthenticated HTTP access to PeopleSoft endpoints, bulk data export patterns from HR/payroll modules, and unexpected session creation between May 27 and June 9, 2026.
7. Sources
- BleepingComputer — Nissan discloses employee data breach linked to Oracle zero-day attacks — https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/ — 2026-06-29
- The Register — Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs — https://www.theregister.com/security/2026/06/29/nissan-says-oracle-peoplesoft-break-in-may-have-spilled-payroll-records-ssns/5263534 — 2026-06-29
- The Register — ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day — https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443 — 2026-06-11
- SecurityWeek — Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks — https://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/ — 2026-06 (date not specified)
- BleepingComputer — Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks — https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/ — 2026-06
- BleepingComputer — Oracle mitigates PeopleSoft zero-day exploited in data theft attacks — https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ — 2026-06
- Cybersecurity Dive — ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft — https://www.cybersecuritydive.com/news/shinyhunters-exploitation-critical-flaw-oracle-peoplesoft/822796/ — 2026-06
8. Adverse Trace position
Severity: HIGH. CVE-2026-35273 is a CVSS 9.8 critical unauthenticated RCE in a widely deployed enterprise platform, actively exploited in the wild against 100+ organisations with confirmed data exfiltration at scale. The vulnerability is not CISA-KEV-listed in the verified reference data, but exploitation is confirmed by Mandiant and the scale of victim disclosure is corroborated across multiple independent sources. Attribution to ShinyHunters is unconfirmed — the group has no MITRE ATT&CK profile and the attribution rests on the group's own claims and journalistic reporting; Nissan has not confirmed the link. EMEA financial services clients running Oracle PeopleSoft should treat this as an immediate priority: patch all instances, restrict external access, and audit for compromise during the May 27–June 9 window. Clients using Oracle-managed PeopleSoft hosting should engage Oracle as a third-party ICT provider under DORA Art. 28 and confirm patch status in writing. Adverse Trace will continue monitoring for IOC publication, CISA-KEV listing, and confirmation of the Nissan–CVE-2026-35273 link, and will issue an update if technical indicators emerge.
Published via PulseTrace — Adverse Trace threat intelligence.