Investigation · Employee & Payroll Data

Nissan Employee Data Breach Investigation

Hall Attorneys is evaluating potential claims for current and former Nissan employees after a 2026 Oracle PeopleSoft incident involving payroll, identity, banking, tax, and dependent information.

Affected-person count
Not confirmed

Nissan says its scope review remains ongoing

Reported access period
May 27–June 9

2026 dates listed by the California AG

Primary group
Employees

current and former workers in four countries

Answer at a glance

What happened in the Nissan employee data breach?

Nissan Americas says it uses Oracle PeopleSoft to manage payroll, tax administration, and other personnel records. Its notice says the system experienced a cyber incident in which data was unlawfully accessed on Nissan systems.

Nissan says it learned that it was directly targeted in a broader attack involving an unknown PeopleSoft vulnerability. The California Attorney General lists May 27 through June 9, 2026, as the known breach period.

The company's June 25 notice says the investigation was still in an early stage. Nissan did not provide a reliable affected-person count and said people whose specific information was exposed would receive additional communication.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Reported access period

    The California Attorney General lists these dates for Nissan's breach. Mandiant observed the broader PeopleSoft exploitation campaign during the same period.

  2. Oracle and Mandiant disclose the vulnerability

    Oracle issued its CVE-2026-35273 alert, and Mandiant described a ShinyHunters campaign using the vulnerability before a patch was available.

  3. Nissan submits employee notices

    Nissan North America submitted current- and former-employee communications to the California Attorney General and said its scope investigation remained ongoing.

Reported data categories

What information was involved?

Nissan's notice describes high-risk employee and dependent information. It says the categories are preliminary and that affected individuals will receive more specific details as the investigation continues.

Important distinction

The public notice does not establish that every category was exposed for every employee. It also does not provide a reliable total number of affected people.

Identity details
Social Security, Social Insurance, or national identification numbers
Financial and payroll
Banking information, payroll, financial data, and tax data
Contact information
Employee contact information
Family information
Dependent and beneficiary information

Who may want to contact us

Current and former Nissan employees

Nissan's notice identifies current and former employees in the United States, Canada, Mexico, and Brazil. Individual exposure will depend on the results communicated to each employee.

Current Nissan employees in the United States, Canada, Mexico, or Brazil

Former employees whose historical PeopleSoft personnel records may have been retained

Dependents or beneficiaries whose information may appear in employee records

People experiencing payroll-themed phishing, tax fraud, identity theft, account misuse, financial loss, monitoring costs, or lost time

What to preserve

Keep Nissan notices, employment records, and financial alerts

Preserve relevant records, but do not send passwords, complete bank-account numbers, Social Security or national ID numbers, tax forms, or unredacted credit reports through ordinary website forms.

Notices and monitoring offers

Keep the complete Nissan notice, envelope, email, enrollment instructions, deadline, and any later updates.

Relationship records

Preserve records showing your current or former employment with Nissan and any dependent or beneficiary relationship reflected in Nissan's records, including dated account, enrollment, employment, alumni, transaction, or correspondence records.

Information held about you

Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.

Suspicious communications

Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.

Credit and account records

Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.

Time, expenses, and harm

Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the PeopleSoft access, the employee and dependent data involved, Nissan's notice and monitoring response, and concrete harms reported by affected workers.

  1. Which Nissan entities, countries, PeopleSoft systems, and connected storage areas were affected
  2. When unauthorized access began and ended and when Nissan learned it was directly targeted
  3. How many current employees, former employees, dependents, and beneficiaries were affected
  4. Which identity, banking, payroll, tax, contact, dependent, and beneficiary fields were associated with each person
  5. What monitoring or restoration services were offered in each country and for how long
  6. Whether affected people experienced targeted phishing, tax or identity fraud, financial loss, monitoring costs, or time loss

Public records reviewed

Sources for the Nissan incident

Nissan's own notice and the California filing are the principal sources for individual scope. Oracle and Mandiant provide technical context for the broader PeopleSoft campaign.

California Attorney General ·

Submitted Breach Notification Sample

Lists Nissan North America, the May 27 through June 9 breach dates, and links to current- and former-employee communications.

Read source: Submitted Breach Notification Sample

Oracle ·

Security Alert Advisory — CVE-2026-35273

Oracle says the PeopleSoft PeopleTools vulnerability is remotely exploitable without authentication, may allow remote code execution, and affects supported versions 8.61 and 8.62.

Read source: Security Alert Advisory — CVE-2026-35273

Contact the firm

Are you a current or former Nissan employee?

Contact Hall Attorneys with your general employment dates and country, whether you received notice, and a summary of suspicious activity or loss. Do not include passwords, bank details, tax records, government identifiers, or identification documents in an initial message.

Contact Hall Attorneys

Frequently asked questions

Nissan breach FAQ

Is this a filed Nissan data breach lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning this Nissan incident.

How many Nissan employees were affected?

Nissan's public notice does not provide a reliable affected-person count. It says the investigation remains ongoing and affected people will receive more specific communication.

Who may be affected?

Nissan says the incident affects current and former employees in the United States, Canada, Mexico, and Brazil. Dependent and beneficiary information may also be involved.

What information may have been exposed?

Nissan lists contact and banking information, Social Security, Social Insurance or national ID numbers, financial and tax data, and dependent or beneficiary information.

What support did Nissan announce?

Nissan said it was arranging free credit or dark-web monitoring for affected individuals where available. Recipients should rely on the terms and deadlines in their own follow-up notice.

Attorney Advertising

Hall Attorneys is not affiliated with Nissan Americas or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.