June 26, 2026: The National Association of Insurance Commissioners (NAIC) confirmed that ShinyHunters breached its environment through an Oracle PeopleSoft zero-day, published stolen data after NAIC refused to pay, and triggered a temporary suspension of investment risk designations that U.S. life insurers rely on for capital planning.
What the NAIC confirmed
Per the NAIC's security incident update page, unauthorized access was identified June 11, 2026 via a PeopleSoft vulnerability exploited in a broader campaign affecting multiple organizations. NAIC engaged outside counsel, FBI coordination, and cybersecurity experts; operations largely returned to normal though online PeopleSoft invoice payment remained unavailable.
Data accessed or acquired, based on NAIC findings to date:
- Statutory financial reporting information already publicly available through state websites, InsData, or resellers
- Credit rating agency data, including rating determinations of insurer investments (not rationale reports)
- Potentially outdated technical logs or configuration information
NAIC states no PII, payment, or banking information was accessed. Core regulatory systems—including SERFF, OPTins, UCAA, NIPR, producer data, and policyholder information—were not compromised.
ShinyHunters publishes the data
After NAIC declined to pay, ShinyHunters published data on its leak site. The group initially overstated scope but revised its analysis to describe roughly 264,000 insurer regulatory filing PDFs (2017–2024), bulk-order purchaser records, rating-agency files from Moody’s, S&P, Fitch, and others, and AWS infrastructure artifacts. DataBreaches.net and the Financial Times report the breach forced credit rating agencies to pause data sharing, causing NAIC to suspend assigning investment risk designations—a move with direct capital-charge implications for U.S. life insurers.
What was not exposed
NAIC explicitly lists systems and data categories confirmed not accessed: state insurance department systems, SERFF rate/form filing, OPTins premium tax, UCAA, employee personal data, electronic funds transfer, risk-based capital data, policyholder information, producer data, and event registration payments.
Who is at risk?
NAIC says no consumer PII was involved. Risk concentrates on:
- Insurers facing capital-planning disruption from suspended investment designations
- Rating agencies reassessing data-feed security with NAIC
- Anyone receiving phishing impersonating NAIC—report suspicious messages to [email protected]
Action items
- Insurers: Monitor AVS+ for NAIC designation-process updates.
- Do not trust leak-site downloads or extortion emails claiming NAIC origin.
- Report phishing to [email protected]; preserve the message.
Canonical record: NAIC ShinyHunters 2026 on BreachHistory.
Sources: NAIC security update, DataBreaches.net, BleepingComputer