A sophisticated campaign orchestrated by the threat group UNC6240 specifically targeted the PSEMHUB component of PeopleSoft to gain initial access to corporate enterprise resource planning systems. This intrusion marks a significant escalation in how modern threat actors exploit foundational business software to compromise global supply chains and automotive giants like Nissan. The breach was not merely an opportunistic strike but a calculated operation by the group ShinyHunters, who identified structural weaknesses in the way ERP systems handle unauthenticated requests. By bypassing traditional perimeter defenses, the attackers gained a foothold that allowed them to sift through mountains of sensitive data belonging to thousands of employees across the Americas. This event highlights the precarious nature of corporate cybersecurity when deep-seated vulnerabilities in legacy software remain unpatched while organizations move toward hybrid cloud environments. The impact of such a failure extends far beyond technical downtime, affecting the lives of individuals whose personal identities are now at risk in the digital underground.
Technical Exploitation and System Vulnerability
The Mechanics of the PeopleSoft Zero-Day
At the core of this widespread disruption lies CVE-2026-35273, a vulnerability that exists within the Oracle PeopleSoft PeopleTools environment, specifically affecting the way the system processes incoming HTTP requests. This flaw is particularly dangerous because it facilitates an unauthenticated Server-Side Request Forgery, which essentially tricks the server into performing actions on behalf of the attacker without requiring a valid login. In many enterprise environments, PeopleSoft is integrated deeply with internal networks, making it an ideal jump box for further exploitation. Once the SSRF is successfully executed, attackers can escalate their privileges to achieve Remote Code Execution. This transition from a simple request error to full system control happens almost instantaneously, allowing malicious actors to execute arbitrary commands with administrative rights. For a system that manages payroll, benefits, and sensitive employee records, the implications of such high-level access are catastrophic for any organization’s data integrity.
Timeline and Scope of the ShinyHunters Campaign
The exploitation campaign was not limited to a single target but was instead a broad, industrialized effort that affected over 100 major organizations and more than 300 individual PeopleSoft instances globally. This scale suggests a level of coordination and resource allocation that is typical of highly organized cybercriminal syndicates. At Nissan, the breach occurred during a critical two-week window in mid-2026, a period of extreme vulnerability that existed between the active exploitation by threat actors and the eventual deployment of an emergency patch by Oracle. During this time, the attackers maintained a silent presence, methodically extracting data while security teams were still identifying the source of the anomaly. This timeframe illustrates the dangerous patch gap that exists in modern enterprise software management, where the speed of exploitation often outpaces the ability of vendors to distribute fixes and for IT departments to implement them across diverse, complex environments.
Attacker Methodology and Post-Infiltration Tactics
Stealth, Persistence, and Lateral Movement
To remain undetected within Nissan’s complex network infrastructure, ShinyHunters employed a strategy of blending in with legitimate administrative traffic. After the initial compromise of the PeopleSoft server, they deployed custom remote management agents that were carefully disguised as standard Microsoft Azure services. This camouflage is highly effective against automated monitoring systems, which often whitelist common cloud-related processes to prevent false positives. By masquerading as an essential cloud component, the attackers were able to establish a persistent backdoor that allowed them to re-enter the network even if the initial entry point was secured. This level of operational security demonstrates a deep understanding of modern IT operations, where the lines between internal infrastructure and third-party cloud services are increasingly blurred. Following the establishment of persistence, the threat actors pivoted to internal reconnaissance, using specialized scripts to navigate the network.
Nissan’s Defensive Response and Recovery Measures
Once the intrusion was detected, Nissan immediately initiated a comprehensive incident response protocol that involved collaboration with federal law enforcement agencies and specialized third-party cybersecurity firms. The priority was to isolate the affected systems and prevent further data loss, which led to the implementation of strict network restrictions across the corporate infrastructure. Looking ahead, the incident serves as a stark reminder for all enterprises that relying on the inherent security of legacy ERP systems is no longer a viable strategy in a world of persistent zero-day threats. Organizations should prioritize a zero-trust architecture where access is continuously verified and sensitive data is encrypted both at rest and in transit. Implementing regular, automated vulnerability scanning and maintaining a rapid patching cycle are no longer optional tasks but critical components of corporate survival. Ultimately, the Nissan breach illustrates that the strength of a company’s defense is only as robust as its software.






