The National Association of Insurance Commissioners (NAIC), the U.S. standard-setting and regulatory support organization for state insurance departments, disclosed a significant data breach on June 17, 2026, after unauthorized access to its systems was identified on June 11. The breach, which affected the insurance industry, was caused by a zero-day vulnerability in Oracle PeopleSoft software that was being actively exploited by the ShinyHunters ransomware group.
Oracle released a security alert on June 10, 2026, addressing CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in PeopleSoft PeopleTools. The NAIC uses PeopleSoft primarily for internal financial reporting purposes, but attackers were able to use the vulnerability to gain temporary access to certain data storage areas before the organization detected and contained the breach.
According to the NAIC’s security update, the unauthorized party exploited the zero-day vulnerability—a flaw unknown to the software developer at the time of the attack—as part of a broad campaign affecting multiple organizations. The breach resulted from this widespread vulnerability exploitation, which affected over 100 organizations and 300 individual instances before Oracle released an emergency patch on June 10.
Scope of Exposed Data and Industry Impact
ShinyHunters, the extortion group responsible for the attack, posted 3.1 terabytes of allegedly stolen data online on June 25-26, 2026. According to the group’s claims, reviewed after what ShinyHunters said was a human verification process, the dataset includes more than 264,000 insurer regulatory filing PDFs spanning property, casualty, health, and life insurance companies between 2017 and 2024.
The leaked data also reportedly contains approximately 45,000 files from major credit rating agencies including Moody’s, Fitch, S&P, Kroll, DBRS, AM Best, Egan-Jones, and HR Ratings. Additionally, ShinyHunters claimed to have obtained around 2,000 customer and bulk order records containing names, email addresses, and payment transaction identifiers, along with production AWS infrastructure logs and cloud configuration files.
The NAIC confirmed that no personally identifiable information (PII) or payment and financial account information, including credit card or banking information, was accessed. The organization also confirmed that critical regulatory systems were not compromised, including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), Uniform Certificate of Authority Application (UCAA), Enterprise Data Platform (EDP), and Regulatory Data Collection (RDC).
However, the breach has had operational consequences for the insurance industry. Due to the incident, certain credit rating agencies paused their data feeds to the NAIC, prompting the NAIC to temporarily suspend assigning investment risk designations to insurer investments. This suspension affects how state insurance regulators evaluate the financial health and credit ratings of insurance companies.
The NAIC engaged outside cybersecurity experts and coordinated with the FBI to investigate the breach. According to the organization’s June 26 update, affected systems have been remediated, and the NAIC has taken additional steps to strengthen its defenses. The organization is working with an external data consultant to compare the scope and type of data posted by ShinyHunters with its own analysis—a process the NAIC indicated could take several weeks.
Sources
- NAIC — official security incident updates and disclosures on June 17, 18, 23, 25, and 26, 2026
- Cybernews — reporting on ShinyHunters’ 3.1TB data dump and NAIC breach confirmation with details on exposed data categories
- Oracle — security alert CVE-2026-35273 disclosure on June 10, 2026
- Arctic Wolf — analysis of CVE-2026-35273 active exploitation by ShinyHunters
- Rapid7 — reporting on active exploitation of Oracle PeopleSoft zero-day vulnerability












