Last updated 2 weeks ago
Nissan, a Japanese automotive manufacturer, disclosed a data breach affecting employee data. The breach was publicly reported on July 5, 2026, with the disclosure date inferred as July 2026. The number of affected records and the specific employee population impacted were not disclosed.
The attack leveraged a zero-day vulnerability in Oracle PeopleSoft, exploited as part of a broader campaign targeting the software. The initial access vector was vulnerability exploitation, allowing unauthorized access to Nissan's PeopleSoft systems. The attackers exfiltrated employee data, though the specific types of data compromised were not detailed in the article. No threat actor group was attributed to the incident.
No post-incident developments such as regulatory actions, litigation, ransom payments, or containment milestones were reported in the article.
Exploitation of Oracle PeopleSoft zero-day vulnerability
Nissan's breach underscores the critical need for timely patching of enterprise software, particularly for widely used platforms like Oracle PeopleSoft. Organizations should prioritize vulnerability management programs that include rapid assessment and remediation of zero-day exploits, especially when targeting HR and employee data systems. The incident also highlights the importance of monitoring for unusual access patterns and implementing network segmentation to limit lateral movement from compromised applications.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector