Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-Day: What Was Reportedly Exposed & What To Do
Nissan disclosed on June 29, 2026 that an Oracle PeopleSoft zero-day vulnerability was used to access employee data. Employees should check their records and take protective steps if their contact information, banking details, Social Security numbers, financial and tax records, or dependent and beneficiary information may have been exposed.
Breaking down the breach
Nissan reported that attackers used an Oracle PeopleSoft zero-day vulnerability to access systems containing employee data. The company stated that the intrusion affected records of current and former employees across four countries in the Americas.
Notifications have been issued to those individuals. Nissan has filed required reports with the California Attorney General and continues to investigate the extent of the access. No further details on the timeline of the intrusion or the volume of records involved have been released.
How a breach like this happens
Zero-day vulnerabilities are flaws in software that are unknown to the vendor at the time of exploitation. Attackers can use them to gain entry to internal systems before patches become available.
Enterprise platforms such as Oracle PeopleSoft often store large volumes of human-resources data. Once initial access is obtained, attackers may move laterally within the network to locate and copy files containing personal identifiers and financial records.
Nissan and its sector
Nissan is a multinational automotive manufacturer that employs thousands of people across multiple countries. Like other large employers, it maintains records necessary for payroll, tax reporting, benefits administration, and regulatory compliance.
These records routinely include contact details, government identifiers, banking data, and information about dependents. A compromise of such systems can therefore expose data that individuals use for identity verification and financial transactions.
What was likely exposed
Nissan has identified the categories of information accessed during the incident. The precise contents of any individual record remain unconfirmed pending the outcome of the ongoing investigation.
- employee contact information
- banking information
- Social Security numbers
- financial and tax information
- dependent and beneficiary information
The real-world impact
Individuals whose Social Security numbers and banking details are involved may experience attempts at identity theft or fraudulent account activity. Tax and financial records can also be used for targeted scams or unauthorized filings.
For the organization, the incident adds to the administrative burden of regulatory notifications, internal reviews, and potential legal proceedings. The long-term effects on affected employees depend on how the exposed data is used after the breach.
Were you affected?
Current and former Nissan employees in the listed countries should review any direct notifications sent by the company. They can also monitor bank and tax accounts for unusual activity and consider placing fraud alerts with credit reporting agencies.
Readers can run a free exposure scan of their email address against known breach data to check for additional appearances of their information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Lapsus$ Leaks Vodafone Source Code and Database CredentialsUnsafe ransomware group claims Deutsche Bank data breachBrazilian IT Firm Service IT Breached by WorldLeaksChaos Ransomware Claims Breach of Universal Plant ServicesLatest breaches
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.