Overview
- The National Association of Insurance Commissioners confirmed on June 26 that attackers used a PeopleSoft zero-day to access part of its environment and that the exposed material was mainly public statutory reports, credit-rating files, and technical logs with no evidence of PII or payment data.
- Nissan filed breach notices at the end of June saying it was targeted in the same PeopleSoft campaign and that its investigation is ongoing while it assesses whether current and former employee contact, banking, Social Security and other personal information were accessed.
- Security firms and reporting indicate the flaw is tracked as CVE-2026-35273, Oracle issued an out-of-band advisory, and Mandiant says exploitation occurred in late May through early June, affecting cloud and on-premises PeopleSoft instances.
- The hacking group ShinyHunters has claimed responsibility for a wide sweep that it says touched more than 100 organizations, but the group later revised parts of its inventory and victim and attacker accounts differ on the volume and sensitivity of stolen files.
- The campaign forced emergency mitigations, paused some insurance and rating feeds, spurred FBI coordination and external forensic work, and left experts warning that victims should assume possible persistence and perform full incident response and notifications.