CSIDB logo
Incident

National Association of Insurance Commissioners

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-23 20:02

Linked entities

Victim
National Association of Insurance Commissioners
Threat actors
1 actor
Sources
6 sources

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

The National Association of Insurance Commissioners experienced a breach after attackers exploited a zero‑day vulnerability in its Oracle PeopleSoft platform, gaining access to publicly available statutory financial reporting data, credit rating agency information, and technical logs while confirming that personal, payment, and core regulatory systems remained uncompromised. The intruders later posted portions of the data online, prompting the organization to engage external experts, coordinate with the FBI, and temporarily suspend certain services as it worked to verify the scope and strengthen defenses.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 11, 2026, the National Association of Insurance Commissioners detected unauthorized access to its systems. The breach was traced to a zero‑day vulnerability in Oracle PeopleSoft that the association uses for internal financial reporting. The vulnerability, identified as CVE‑2026‑35273, allowed unauthenticated remote code execution and was part of a broad campaign affecting multiple organizations. The ShinyHunters cybercrime group claimed responsibility for the intrusion.

After gaining entry, the attackers accessed publicly available statutory financial reporting information, credit rating agency data including rating determinations of insurer investments, and technical information such as outdated logs and configuration data. They did not obtain personally identifiable information, payment or financial account data, employee data, electronic funds transfer, risk‑based capital data, policyholder information, producer data, or event registration payment information. The association confirmed that systems such as SERFF, OPTins, UCAA, EDP, RDC, NIPR, Teammate, and state‑based systems were not compromised. Some credit rating agencies paused their data feeds, prompting NAIC to temporarily suspend assigning designations to insurer investments.

NAIC said the breach was promptly contained after detection and the attacker’s access was blocked. The association engaged outside counsel and cybersecurity experts, contacted its cyber insurance carrier, and coordinated with the FBI. It worked with an external cybersecurity partner to compare the data posted online by the attackers with its own analysis and posted updates on its website. Online invoice payment via PeopleSoft remained unavailable while other operations returned to normal, and NAIC met with credit rating providers to provide third‑party assurances that its systems were secure.

Sources

Sources available to members: 6 sources.

CSIDB