The Nissan data breach has prompted the automaker to investigate a cyberattack targeting an Oracle PeopleSoft environment that stores employee information. The intrusion forms part of a wider hacking campaign against organizations running vulnerable Oracle enterprise software. Nissan continues to examine the incident to determine what information the attackers accessed and how many people the breach affected.
The automaker continues to examine the incident to determine exactly what information the attackers accessed and how many people the breach affected.
Employee Information May Be at Risk
Nissan believes the attackers accessed records belonging to current and former employees in several North American countries.
The exposed information may include names, contact details, dates of birth, government-issued identification numbers, payroll records, tax information, bank account details, and beneficiary information. Investigators continue reviewing affected systems to determine the full extent of the exposure.
So far, Nissan has not found evidence that the attackers accessed customer information.
Hackers Exploited an Oracle PeopleSoft Flaw
Investigators say the attackers entered Nissan’s environment by exploiting a previously unknown Oracle PeopleSoft vulnerability.
The same flaw enabled attackers to compromise multiple organizations before administrators could deploy Oracle’s security updates. Security researchers believe threat actors actively searched for vulnerable PeopleSoft servers and moved quickly after discovering exposed systems.
Nissan Continues Its Response
Nissan activated its incident response plan as soon as it discovered the intrusion.
The company secured affected systems, hired external cybersecurity experts, and continues working with Oracle to understand how the attackers gained access. Nissan also plans to contact anyone whose personal information the investigation identifies as affected.
Nissan Data Breach Reflects a Wider Threat
The Nissan data breach highlights the growing danger posed by attacks against enterprise software platforms that manage human resources and payroll data.
Organizations running Oracle PeopleSoft should install the latest security updates, review internet-facing systems for unauthorized activity, and closely monitor HR platforms for suspicious behavior. The Nissan data breach demonstrates how quickly attackers can exploit newly discovered vulnerabilities when organizations delay critical patches.


0 responses to “Nissan Data Breach Confirmed After Oracle PeopleSoft Zero-Day Attack”