← All news

breach

Nissan Payroll Data Breached in Oracle PeopleSoft Attacks

2026-06-29

Nissan has started writing to current and former employees in the United States, Canada, Mexico and Brazil to tell them their personnel records were caught up in the wave of Oracle PeopleSoft attacks linked to the ShinyHunters extortion crew. The automaker uses PeopleSoft to run payroll, tax and HR, which is exactly the kind of system you do not want quietly bleeding records into someone else's hands.

According to notifications filed with the California Attorney General, attackers may have accessed contact details, bank account information, Social Security and Social Insurance numbers, National Identification numbers, tax records, and information on dependents and beneficiaries. The investigation is still in its early days, so Nissan has not yet confirmed exactly who is affected or how badly. The list of data types alone tells you enough about why this one matters.

What the wider campaign looks like

The campaign behind the Nissan breach is now reasonably well mapped. Mandiant has confirmed that ShinyHunters exploited a zero-day in Oracle PeopleSoft, tracked as CVE-2026-35273, between 27 May and 9 June. More than 100 organisations were hit, the bulk of them in the education sector. Oracle has shipped emergency mitigations, though it has still not publicly acknowledged that the flaw was used in active attacks. Leaked data has already shown up online for Nottingham University and the National Association of Insurance Commissioners, so the silence is not buying anyone much.

Nissan's response

Nissan says it has cut off the unauthorised access, brought in outside incident responders, and tightened the controls around the payroll system itself. Pay slip access and direct deposit changes are now restricted to corporate network or VPN connections, with additional identity verification before payroll requests are processed. Affected staff will be offered credit and dark web monitoring where local rules allow it.

It is a sensible set of changes, and most of them look like the sort of thing that would have been useful to have in place before the breach rather than after.

Why payroll keeps getting hit

The uncomfortable part of this story is how ordinary the target was. Payroll and HR platforms rarely top the threat-modelling list. They are not customer-facing. They are not where intellectual property lives. They tend to be administered by finance or HR teams who, quite reasonably, are not running tabletop exercises on zero-day exploitation.

And yet they hold, in one neat package, almost everything an extortion crew wants:

  • Identity data: full names, addresses, dates of birth, government ID numbers.
  • Financial data: bank account and routing details for direct deposit.
  • Family data: dependents and beneficiaries, useful for downstream social engineering.
  • Tax records: enough to file fraudulent returns or build convincing impersonations.

That combination is why ShinyHunters and groups like them keep coming back to HR systems. The data is high value, the controls are often softer than the crown-jewel systems next door, and the affected population is captive. Employees cannot exactly opt out of their employer's payroll provider.

For anyone running a similar stack, the Nissan disclosure is a useful nudge to look at where personnel data actually sits, who can reach it, and whether the controls around it match the value of what is inside. The attackers have already figured out the answer.

Nissan Payroll Data Breached in Oracle PeopleSoft Attacks | RiskSense