Last Update: 08/01/2026 at 1:00 PM EST

Threat Actors Exploit Oracle PeopleSoft

Coverage from IT Brew, Gblock, and others

Articles

18

Active Days

11

The Topic

Threat Actors Exploit Oracle PeopleSoft topic image

Threat actors exploited an Oracle PeopleSoft PeopleTools zero-day, tracked as CVE-2026-35273, to access sensitive personnel records held by enterprise HR and payroll systems. Nissan reported potential exposure of employee and dependent information across several countries, while reporting linked the broader campaign to ShinyHunters and identified additional affected organizations. The incidents show how compromise of HR platforms can expose identity, payroll, tax, banking, and benefits data, prompting containment measures, vendor coordination, and credit or identity monitoring for affected individuals.

First Article: 06/26/26

Latest Article: 07/06/26

Summary

  • CVE-2026-35273 was exploited against Oracle PeopleSoft PeopleTools in a data-theft campaign.
  • Nissan reported potential exposure of current and former employee data in the United States, Canada, Mexico, and Brazil.
  • Potentially affected Nissan records include Social Security and national identification numbers, banking, payroll, financial, tax, dependent, and beneficiary information.
  • Reporting attributed the broader campaign to ShinyHunters, which claimed hundreds of PeopleSoft instances across roughly 100 organizations were breached; those figures remain attacker claims.
  • Some organizations reportedly began restricting payroll and direct-deposit changes to corporate networks or secured VPNs while adding identity verification.
  • Kubota separately disclosed unauthorized access to HR files containing Social Security numbers, bank details, government IDs, and benefits records, but no confirmed link to the PeopleSoft campaign was provided.

History

07/23/2026

The main update is a modest reframing of the campaign: reporting now more explicitly links the PeopleSoft thefts to ShinyHunters and adds that some organizations have begun tightening access controls and identity checks. The Nissan and Kubota incidents are otherwise broadly consistent, with the Kubota case still presented as separate rather than connected.

07/22/2026

The update adds a concrete zero-day attribution and timeline for the Oracle PeopleSoft campaign, plus broader claims about scale and remediation at Nissan. It also sharpens the Kubota disclosure with more specific exposed data types and timing.

Featured

Additional Articles