Menu
Browse
Date

Jun 2026

Location

United States of America

Status

Unknown

Updated

2026-07-16 01:18

Timeline
Occurred
Jun 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

The National Association of Insurance Commissioners disclosed a cyber incident resulting from a zero‑day vulnerability in its Oracle PeopleSoft system that was exploited by a ransomware group claiming to have exfiltrated 3.1 terabytes of data including internal systems such as SERFF, OPTins, UCAA, EDP and RDC. Subsequent forensic analysis concluded that no personally identifiable information, payment data, employee records, policyholder or producer information, risk‑based capital data or electronic funds were accessed, and that the claimed technology assets were not actually exfiltrated. The organization engaged external cybersecurity experts, contacted its cyber insurer and coordinated with the FBI, contained the breach, remediated affected systems and is working with external partners to verify any published data against its own records, while confirming that state insurance department systems remained unaffected.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

OnJune 11 2026 the National Association of Insurance Commissioners detected a cyber intrusion that exploited a zero‑day vulnerability in Oracle PeopleSoft, the system it primarily uses for internal financial reporting, and promptly contained the incident after detection. The association immediately engaged outside counsel and cybersecurity experts, initiated coordination with the Federal Bureau of Investigation, and notified its cyber‑insurance carrier. An internal investigation concluded that no personally identifiable information, payment information, employee data, electronic funds transfer, risk‑based capital data, policyholder information, producer data, or event registration payment information was accessed, and that the systems of state insurance departments remained unaffected. Cybersecurity experts remediated the affected systems and took additional steps to shore up defenses, while the association began meeting with credit‑rating providers to provide third‑party assurances that its systems were secure and stated it would engage those experts to compare any publicly released data with its own analysis if the attackers released the stolen material.

Cyber Incident Image

On June 17 2026 the NAIC posted its first public notice on its website, stating that the data taken earlier in the month from its information technology systems had been published online by the hackers responsible and that it was actively working with an external cybersecurity partner to compare the scope and type of data posted with its own analysis, promising to post updates when available. Multiple online resources attributed the breach to the ShinyHunters ransomware group, which claimed to have stolen 3.1 terabytes of data—more than 105,000 files—and asserted that it had obtained technology provided by the NAIC, including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), Uniform Certificate Authority Application (UCAA), Enterprise Data Platform (EDP), and Regulatory Data Collection (RDC). Independent cybersecurity experts involved in the breach analysis confirmed that this asserted technology was not actually taken. The NAIC reiterated that its internal investigation found no access to employee data, electronic funds transfer, risk‑based capital data, policyholder information, producer data, or event registration payment information. The association also noted that it had been targeted by criminals and was addressing an ever‑changing cyber risk environment.

The National Association of Mutual Insurance Companies (NAMIC) observed that the NAIC should undertake a concerted effort to assess concentration risk and appropriate mitigation steps, and in a letter to the NAIC president noted that the association had not issued any directed alert beyond its website posting, which came nearly one week after the intrusion was identified, and that it had not followed the standards it imposes on insurers for responding to cybersecurity events. The American Property Casualty Insurance Association (APCIA) wrote to the NAIC expressing the need for clear direction from the NAIC so that APCIA could advise its member companies seeking information about the incident’s scope and implications, and offered its assistance to the NAIC. These statements reflect the perspectives of the respective organizations regarding the NAIC’s handling of the incident. The NAIC continues to work with external partners and law‑enforcement entities to assess the situation and provide updates as they become available.

Sources
Sources available to members
5 sources