United States regulators hit by massive NAIC cyberattack
PUBLISHED Jun 27, 2026, 7:45 AM ET
Read, Watch or Listen
The United States National Association of Insurance Commissioners (NAIC) confirmed on June 26, 2026 that it suffered a major cyberattack attributed to the ShinyHunters cybercriminal group. ShinyHunters claims to have stolen 3.1 terabytes of sensitive data from NAIC systems, raising concerns across the U.S. financial and insurance sectors about exposure of regulatory and operational information. Investigators from Google’s Threat Intelligence Group and Mandiant report the attackers exploited a zero-day vulnerability in Oracle PeopleSoft, which was patched by Oracle on June 10, 2026. NAIC detected unauthorized access on June 11 and publicly disclosed the incident on June 17, before confirming the breach’s full scale on June 26.
By Sidra | JQJO News
Timeline of Events
- May 27, 2026 ShinyHunters exploits Oracle PeopleSoft zero-day
- June 10, 2026 Oracle issues emergency PeopleSoft security patch
- June 11, 2026 NAIC detects unauthorized network access
- June 11, 2026 Internal investigation and containment efforts begin
- June 17, 2026 NAIC publicly discloses cybersecurity incident
- June 26, 2026 ShinyHunters claims 3.1 terabytes stolen
- June 26, 2026 NAIC confirms large-scale cyberattack impact
News Intelligence
- The NAIC cyberattack could expose your insurance data. If you've interacted with any U.S. insurance regulator, your personal and financial information might be at risk. Check your accounts for unusual activity. Stay vigilant.
Comments