---
title: "Nissan / PeopleSoft Breach: When HR Is Also You… | Firevault"
url: https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary
description: "Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to…"
lang: en-GB
---

Opinion · Commentary · 4 July 2026

# Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository

Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to ShinyHunters. Mark Fermor on why HR systems keep becoming citizen-scale breaches.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnissan-oracle-peoplesoft-shinyhunters-commentary
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnissan-oracle-peoplesoft-shinyhunters-commentary&text=Nissan%20%2F%20PeopleSoft%20Breach%3A%20When%20HR%20Is%20Also%20Your%20Financial%20Data%20Repository%0A%0ANissan%20Americas%20has%20confirmed%20employee%20SSNs%2C%20banking%20and%20tax%20data%20were%20exposed%20through%20the%20Oracle%20PeopleSoft%20zero-day%20(CVE-2026-35273)%20campaign%20linked%20to%20ShinyHunters.%20Mark%20Fermor%20on%20why%20HR%20systems%20keep%20becoming%20citizen-scale%20breaches.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnissan-oracle-peoplesoft-shinyhunters-commentary

Image: Stylised HR and payroll records floating in a dark server room with severed data cables, illustrating an enterprise HR breach (https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg)

Stylised HR and payroll records floating in a dark server room with severed data cables, illustrating an enterprise HR breach

Why it matters

## What this means for organisations holding critical data

Nissan Americas has filed a California Attorney General breach notification confirming that employee records were exposed through the recent Oracle PeopleSoft zero-day campaign, tracked as CVE-2026-35273 and attributed by researchers to the ShinyHunters extortion group.

PeopleSoft is used by Nissan Americas to manage tax administration, payroll and other employee records. The carmaker believes attackers may have taken data on current and former employees across the US, Canada, Mexico and Brazil, including Social Security numbers, banking information, and financial and tax data.

## The facts

- Vector: Oracle PeopleSoft zero-day CVE-2026-35273, exploited before a patch was available.
- Nissan Americas users of PeopleSoft for tax, payroll and other employee records; filing lodged with the California AG.
- Data potentially taken: SSNs, banking information, financial and tax data for current and former employees in the US, Canada, Mexico and Brazil.
- Attribution: ShinyHunters, the extortion group also credited with the wider PeopleSoft campaign said to have targeted 100+ organisations.
- Other confirmed or reported victims: the University of Nottingham, the National Association of Insurance Commissioners (NAIC), Illinois Central College and Moody Bible Institute, with the education sector said to be the most heavily hit.
- Context: Nissan has been hit multiple times in the past year, including the Everest ransomware group's April claim and downstream exposure from the Red Hat data breach (https://fire-vault.com/learn/breaches).

Source: SecurityWeek, Nissan Employee Data Breached in Oracle PeopleSoft Hack (https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/).

## Why this matters

HR and payroll platforms are quietly the most sensitive citizen-scale datasets most enterprises operate. They hold government identifiers, bank account details and tax numbers for the entire workforce and its alumni, spanning every jurisdiction the company employs in.

When a single unauthenticated zero-day lands in that platform, the blast radius is not "some employees". It is every current and former employee across every country the platform served. And unlike customer data, employees cannot walk away from the exposure. Their identifiers do not rotate.

This is why HR platforms have become such a valuable target for extortion groups. One vulnerability, one credential, one dwell period, and the attacker walks out with a decade of workforce identity.

## The structural problem

Every mitigation available in the coverage arrives after the fact. Patch the CVE. Rotate credentials. Notify the regulators. All necessary. None of them recover a copy that has already been staged and exfiltrated.

The dataset itself continued to sit on an internet-reachable enterprise application server, joined at the hip to authentication, integrations and admin tooling. A single unauthenticated vulnerability in that application collapses the entire perimeter around a decade of workforce records at once.

"Enterprise SaaS is hardened" is not a control. It is a bet. When the bet loses, the entire employee population is exposed in a single event.

## The Firevault position

The master record of workforce identity data, and its recovery copies, should not live on the same network path as the operational HR application.

The live PeopleSoft, Workday or SAP HR instance is fine on the wire. That is what it is for. What has no business being on the wire is the archival gold copy that the organisation depends on to restore, audit and reconstruct.

Firebreak enforces that severance at the physical layer. Offline Secure Storage (https://fire-vault.com/offline-secure-storage) holds employee identity archives beyond the reach of a zero-day in the operational system, a compromised administrator, or an extortion group already inside the network. It does not stop the live application from being breached. It stops the breach from becoming permanent, and it preserves an untampered evidentiary copy for regulators and for the eventual restore.

The point is architectural. If your only copy of the workforce identity record is inside the same platform an unauthenticated CVE just landed on, you do not have a backup strategy. You have a hope.

— Mark Fermor, Co-founder and CEO, Firevault

## What HR and IT leaders should do this week

1. Inventory every enterprise application holding Social Security or National Insurance-equivalent numbers, banking details, and tax data for employees. Treat those systems as citizen-scale, not "internal".
2. Separate the archival copy of that data from the operational system at the network layer, not only in backup policy or cloud tiering.
3. Require a physically air-gapped recovery copy for any HR or payroll platform. Cloud immutability is a delay, not a wall.
4. Rehearse a notification drill that assumes an unauthenticated zero-day in the primary HR platform. Time how long it takes to answer: whose data, which jurisdictions, which regulators, and what changed.

## Related from Firevault

- Vulnerabilities and zero-day exposure: https://fire-vault.com/solutions/control/threats/vulnerabilities
- Firebreak: physical severance at the wire: https://fire-vault.com/control/modules/firebreak
- Physical air gap ransomware protection: https://fire-vault.com/learn/physical-air-gap-ransomware-protection

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Commentary

### Revolut handed customer data to criminals for five months. Then came a $3 million ransom demand

Revolut handed sensitive customer data to criminals impersonating an Italian government agency for five months. Now a three million dollar ransom demand has gone public. Mark Fermor argues the real question is not how it happened, but why the process allowed it.

14 Sept 2026 5 min
https://fire-vault.com/news/revolut-fake-government-requests-data-breach-2026

Commentary

### When data theft becomes personal: what we discussed at The Chelmsford Club

Mark Fermor joined the Inner Circle breakfast at The Chelmsford Club to talk about cyber attacks, data theft and what happens when information a business has been trusted to hold ends up in somebody else's hands. The real value of stolen data is not what somebody will pay for it. It is what that information allows them to do next, and the consequence lands personally, professionally and commercially.

9 Sept 2026 20 min
https://fire-vault.com/news/data-theft-becomes-personal-chelmsford-club-inner-circle-2026

Commentary

### Tata / Apple Leak Shows Why Supply-Chain Data Belongs Off the Wire

World Leaks has posted iPhone 18 Pro supplier maps and drop-test photos taken from Apple's Indian manufacturer Tata Electronics. Mark Fermor on why the answer is architectural, not contractual.

4 Jul 2026 4 min
https://fire-vault.com/news/tata-apple-iphone-18-supply-chain-leak-commentary

Commentary

### Conwy Council Breaches Show the Insider Threat Regulators Keep Underestimating

Three separate disciplinary outcomes in one department in twelve months. Mark Fermor on why the Conwy County Council data breaches are a structural warning to every UK local authority, not a one-off.

4 Jul 2026 4 min
https://fire-vault.com/news/conwy-council-insider-data-breach-commentary

Commentary

### FortiBleed Proves the IP-Connected Perimeter is Indefensible

SOCRadar has now tied the FortiBleed credential-harvesting operation directly to INC and Lynx ransomware deployments. Mark Fermor on why physical severance is the only durable answer.

3 Jul 2026 4 min
https://fire-vault.com/news/fortibleed-inc-lynx-ransomware-commentary

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary#webpage",
    "url": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary",
    "name": "Nissan / PeopleSoft Breach: When HR Is Also You…",
    "description": "Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository",
        "item": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository",
    "description": "Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to ShinyHunters. Mark Fermor on why HR systems keep becoming citizen-scale breaches.",
    "url": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/5ad05cd5-6f93-4a37-9082-2667ee1b8922/news-nissan-peoplesoft-hero-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-04T11:00:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary"
    },
    "inLanguage": "en-GB",
    "articleSection": "Commentary",
    "wordCount": 766,
    "keywords": "Nissan, Commentary, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Nissan Americas has filed a California Attorney General breach notification confirming that employee records were exposed through the recent Oracle PeopleSoft zero-day campaign, tracked as CVE-2026-35273 and attributed by researchers to the ShinyHunters extortion group. PeopleSoft is used by Nissan Americas to manage tax administration, payroll and other employee records. The carmaker believes att",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "Was any Firevault customer or system affected by the PeopleSoft campaign?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "No. Firevault is not a user of the affected Oracle PeopleSoft deployment and has no operational role in the Nissan environment. The commentary here is based entirely on the public SecurityWeek reporting and the linked California Attorney General notification, offered as sector analysis rather than incident disclosure."
        }
      },
      {
        "@type": "Question",
        "name": "Would physical severance have prevented Nissan's employee data from being exfiltrated?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Not from the live PeopleSoft instance itself, which by design has to be reachable to be used. What physical severance changes is the fate of the archival copy. If the master record of employee identity data is held on infrastructure that has no live path from the operational application, a zero-day in that application cannot reach it, cannot alter it, and cannot exfiltrate it. That preserves an untampered evidentiary copy for regulators and a clean baseline for restore."
        }
      },
      {
        "@type": "Question",
        "name": "What should an HR or IT leader do this week if they run PeopleSoft, Workday or SAP HR?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Inventory which HR and payroll systems hold Social Security or National Insurance numbers, banking and tax data for current and former employees; separate the archival copy of that data from the operational system at the network layer; require a physically air-gapped recovery copy rather than relying only on cloud immutability; and rehearse a notification drill that assumes an unauthenticated zero-day in the primary HR platform."
        }
      }
    ]
  }
]
```