[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCdWPdfHhhHOpeHkaRGvBJ5zCslYePffu0PAq96lAM7A":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":28,"source":29,"isVerified":4,"isSpamList":30,"isSensitive":4,"severity":31,"processingStatus":32,"logoUrl":33,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a669eb535ce0d2dd5bb5b71","NissanAmericas2026","Nissan Americas 2026 Data Breach","nissan-americas-2026","nissanusa.com",{"name":12,"sector":13,"country":14,"website":10},"Nissan North America Inc.","Automotive","United States","2026-05-27T00:00:00.000Z","2026-07-26T23:56:37.666Z",0,[19,20,21,22,23,24,25,26,27],"Contact information","Banking information","Social Security numbers","Social Insurance numbers","National Identification numbers","Financial information","Tax information","Dependent information","Beneficiary information","\u003Cp>\u003Cstrong>The Nissan Americas 2026 data breach\u003C\u002Fstrong> is a cyber incident in which Nissan North America confirmed unauthorized access to employee records in its Oracle PeopleSoft environment. A filing published by the California Attorney General lists the known breach period as May 27 through June 9, 2026. Nissan said the incident may affect current and former employees in the United States, Canada, Mexico, and Brazil.\u003C\u002Fp>\n\u003Cp>The primary sources are Nissan's notification page and employee letter published by the California Attorney General, while BleepingComputer reported those documents and the technical context of the Oracle PeopleSoft attack campaign. Because the investigation was continuing at the time of the first notice and no exact unique person count was disclosed, LeakData keeps pwnCount at zero to represent an unknown total.\u003C\u002Fp>\n\u003Ch2>How Was the Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>Nissan Americas said it uses Oracle PeopleSoft to manage payroll, tax administration, and other personnel records. Oracle informed Nissan of a cyber event in which threat actors may have obtained personnel records belonging to hundreds of companies. Nissan later learned that it had been specifically targeted and explicitly said that data on its systems had been unlawfully accessed.\u003C\u002Fp>\n\u003Cp>The California Attorney General's filing identifies the organization as Nissan North America Inc. and lists the known breach dates as May 27 and June 9, 2026. Sample notices dated June 25 for current and former employees are published with the same official filing. LeakData does not substitute the campaign-wide organization count for a Nissan-specific affected-person total.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Exposed?\u003C\u002Fh2>\n\u003Cp>Nissan said that, at an early stage of its investigation, it believed some personal employee information had been accessed. The disclosed categories include contact information, banking information, United States Social Security numbers, Canadian Social Insurance numbers or other National Identification numbers, financial and tax information, and dependent or beneficiary information. These classes track the wording in the company's notice.\u003C\u002Fp>\n\u003Cp>The company did not say that every field was exposed for every employee and had not finalized file-level findings when the notice was published. The data classes therefore describe the potential confirmed scope and should not be read as applying uniformly to each person. Passwords, payment cards, health records, driver's licenses, and other fields not separately confirmed are not added to this record.\u003C\u002Fp>\n\u003Ch2>Who May Be Affected?\u003C\u002Fh2>\n\u003Cp>According to Nissan, the incident may affect current and former Nissan employees in the United States, Canada, Mexico, and Brazil. Because dependent and beneficiary details are among the possible data categories, records about some people connected to employees may also be present. The company did not disclose a country-level or global count of unique people whose information was accessed.\u003C\u002Fp>\n\u003Cp>A zero in the pwnCount field does not mean that nobody was affected; it means that no reliable unique total has been published. Oracle's statement that hundreds of organizations may be affected, ShinyHunters' campaign-wide claims, and Nissan's workforce size cannot be used interchangeably. This record can be updated if a verified affected-person total is later released.\u003C\u002Fp>\n\u003Ch2>The PeopleSoft Attack Campaign\u003C\u002Fh2>\n\u003Cp>BleepingComputer connected the incident to a broader data-theft campaign in which CVE-2026-35273 in Oracle PeopleSoft PeopleTools was exploited as a zero-day. Technical findings attributed to Google Mandiant show exploitation between May 27 and June 9 and notification of many organizations. That period aligns with the dates listed in Nissan's official breach filing.\u003C\u002Fp>\n\u003Cp>The report says the ShinyHunters group claimed responsibility for the campaign, but Nissan's employee notice does not name an attacker. LeakData therefore does not present the group attribution as a definitive identity confirmed by the company. What is established for Nissan is that an unknown PeopleSoft vulnerability was involved, the organization was directly targeted, and personnel data was accessed without authorization.\u003C\u002Fp>\n\u003Ch2>Nissan's Response\u003C\u002Fh2>\n\u003Cp>Nissan activated incident-response protocols after learning of the event, communicated with authorities, and engaged external cybersecurity experts. Technical teams secured affected systems, began working with Oracle, and took steps designed to end unauthorized access and prevent further disclosure. The company emphasized that its investigation to determine the scope remained in progress.\u003C\u002Fp>\n\u003Cp>As a precaution, access to pay slips and direct-deposit changes was restricted to company-network computers or secure VPN connections. Additional identity verification for payroll requests was planned. Nissan said it would offer free credit or dark-web monitoring where available and send detailed follow-up notices to individuals whose information is ultimately confirmed as exposed.\u003C\u002Fp>\n\u003Ch2>How to Read This LeakData Record\u003C\u002Fh2>\n\u003Cp>This record does not mean that every global Nissan customer system or connected-vehicle platform was compromised. The confirmed environment is the Oracle PeopleSoft system used by Nissan Americas for employee records, and the disclosed population consists of current and former employees. No confirmed impact to customer accounts, dealer systems, connected-car data, or vehicle telemetry was reported.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that Nissan North America was directly targeted in the May 27–June 9, 2026 PeopleSoft attack; some employee personal information may have been accessed; and current and former employees in four countries fall within the potential scope. Because the exact person count and person-level fields were not yet finalized, this record includes only officially disclosed categories and an unknown total.\u003C\u002Fp>","Oracle PeopleSoft unauthorized access",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fnissan_com.svg"]