Nissan warns of employee data theft via Oracle PeopleSoft zero-day
Source headline: Nissan discloses employee data breach linked to Oracle zero-day attacks
Intelligence Summary
Nissan disclosed that threat actors accessed data tied to current and former employees. The incident was enabled by exploitation of an Oracle PeopleSoft vulnerability. The activity involves data theft attacks previously associated with the ShinyHunters extortion group. Nissan says it is working to assess impact and respond to the exposure. The case highlights ongoing risk from unpatched Oracle PeopleSoft environments and related lateral access paths.
Recommended Action
Inventory where Oracle PeopleSoft runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.