National Association of Insurance Commissioners
Incident posture
Linked entities
- Victim
- National Association of Insurance Commissioners
- Threat actors
- 1 actor
- Sources
- 6 sources
Timeline
Summary
The National Association of Insurance Commissioners experienced a breach after attackers exploited a zero‑day vulnerability in its Oracle PeopleSoft platform, gaining access to publicly available statutory financial reporting data, credit rating agency information, and technical logs while confirming that personal, payment, and core regulatory systems remained uncompromised. The intruders later posted portions of the data online, prompting the organization to engage external experts, coordinate with the FBI, and temporarily suspend certain services as it worked to verify the scope and strengthen defenses.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 11, 2026, the National Association of Insurance Commissioners detected unauthorized access to its systems. The breach was traced to a zero‑day vulnerability in Oracle PeopleSoft that the association uses for internal financial reporting. The vulnerability, identified as CVE‑2026‑35273, allowed unauthenticated remote code execution and was part of a broad campaign affecting multiple organizations. The ShinyHunters cybercrime group claimed responsibility for the intrusion.
After gaining entry, the attackers accessed publicly available statutory financial reporting information, credit rating agency data including rating determinations of insurer investments, and technical information such as outdated logs and configuration data. They did not obtain personally identifiable information, payment or financial account data, employee data, electronic funds transfer, risk‑based capital data, policyholder information, producer data, or event registration payment information. The association confirmed that systems such as SERFF, OPTins, UCAA, EDP, RDC, NIPR, Teammate, and state‑based systems were not compromised. Some credit rating agencies paused their data feeds, prompting NAIC to temporarily suspend assigning designations to insurer investments.
NAIC said the breach was promptly contained after detection and the attacker’s access was blocked. The association engaged outside counsel and cybersecurity experts, contacted its cyber insurance carrier, and coordinated with the FBI. It worked with an external cybersecurity partner to compare the data posted online by the attackers with its own analysis and posted updates on its website. Online invoice payment via PeopleSoft remained unavailable while other operations returned to normal, and NAIC met with credit rating providers to provide third‑party assurances that its systems were secure.
Sources
Sources available to members: 6 sources.