← National Association of Insurance Commissioners (NAIC)

2026 NAIC — ShinyHunters PeopleSoft breach; public statutory filings & rating data stolen

2026 Unknown records affected Share on X

Data compromised

Per NAIC June 26 update: publicly available statutory financial reporting information, credit rating agency investment-designation data (not rationale reports), and potentially outdated technical logs/configuration data; NAIC states no PII, payment, or banking information accessed; SERFF, OPTins, UCAA, and other regulatory systems not compromised

Technical writeup

Verified breach — June 2026. The NAIC confirmed unauthorized access to a portion of its environment on or about June 11, 2026 via an Oracle PeopleSoft zero-day vulnerability exploited in a broader campaign. NAIC engaged outside counsel, FBI coordination, and cybersecurity experts; operations largely returned to normal though online PeopleSoft invoice payment remained unavailable and NAIC temporarily suspended assigning investment risk designations after credit rating agencies paused data feeds. ShinyHunters published data after NAIC declined payment; the group initially overstated scope but revised its leak-site analysis to describe ~264k insurer regulatory filing PDFs (2017–2024), bulk-order purchaser records, rating-agency files, and AWS configuration artifacts—while NAIC's June 26 update emphasizes statutory filings already public via InsData/state sites, rating determinations without rationale reports, and no confirmed PII or payment data. State insurance department systems, SERFF, OPTins, UCAA, NIPR, producer data, and policyholder information were not accessed per NAIC. BreachHistory indexes recordsAffected 0 pending NAIC attestation of affected individuals; document-volume claims remain in actor/trade-press reporting.

Root cause

Unauthorized access via Oracle PeopleSoft zero-day vulnerability identified June 11, 2026; ShinyHunters extortion group published stolen NAIC data after NAIC declined to pay

References