HackingVulnerability ExploitSupply Chain (3P Vendor)TargetedEmployee Data InvolvedZero-DayIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICEMPLOYMENTMediumActive
NISSAN NORTH AMERICA, INC.
bd_58adcf1efb3d57be · schema v1 · pii pii-v1
Full breach record for NISSAN NORTH AMERICA, INC. →Nissan North America Inc. reported a cybersecurity incident involving Oracle PeopleSoft software, where an unknown vulnerability was exploited by threat actors who specifically targeted Nissan. The breach, occurring between May 27 and June 9, 2026, potentially exposed employee personal information including SSNs, banking details, and tax data for current and former employees in the U.S., Canada, Mexico, and Brazil. Nissan activated incident response protocols, engaged experts, and is offering credit monitoring.
California clockConsumers notified Jun 25, 2026 → AG copy submitted Jun 26, 20261d ✓ CA AG copy ≤15d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_57613ef9a6acc173Texas State AGfiled 2026-06-26Candidate
- bd_7e1d6bbb8145148cVermont State AGfiled 2026-06-27(1d gap)Verified
- bd_e41b1e0ee313e724Indiana State AGfiled 2026-06-25(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-625558
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 26, 2026
- Raw hash
- 35118874142d253e7597e8a09e4a94a9566e103ccc31cf8ac49c58664e801bf7
Reporting entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Victim entity
- Name
- NISSAN NORTH AMERICA, INC.norm: nissan north america
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 25, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- In communication with authorities throughout our response to this attack
- Third party
- via Oracle
- Initial access
- supply_chain
Compliance
- Compliance flags
- CA AG copy ≤15d · 1d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status California Consumers notified: Jun 25, 2026→ AG copy submitted: Jun 26, 20261d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.