United States insurance regulators targeted in Oracle hack
PUBLISHED Jun 30, 2026, 9:50 AM ET
Read, Watch or Listen
The National Association of Insurance Commissioners (NAIC), which supports state insurance regulation across all 50 U.S. states, has confirmed it was compromised in a hacking campaign exploiting an Oracle PeopleSoft zero-day vulnerability, tracked as CVE-2026-35273. Oracle issued an out-of-band advisory on June 11, 2026, after Google and others observed active exploitation. NAIC disclosed on June 26 that attackers accessed statutory financial reporting data, credit rating agency information, and technical logs and configuration data. The association said no personally identifiable, payment, or financial account information was exposed and that state insurance departments’ systems were not affected. Extortion group ShinyHunters claims stealing 3.1 TB of data.
By Emily Rhodes | JQJO News
Timeline of Events
- Jun 11 Oracle issues PeopleSoft zero-day advisory
- Jun 11 NAIC detects unauthorized access attempt
- Mid Jun Google confirms zero-day exploitation globally
- Jun 18 ShinyHunters lists NAIC on leak site
- Jun 18 Group claims stealing 3.1 terabytes data
- Jun 26 NAIC posts public security incident notice
- Late Jun NAIC reports only regulatory data accessed
- Late Jun ShinyHunters revises earlier data volume claims
News Intelligence
- Your insurance isn't at risk. The NAIC hack didn't expose personal, payment, or financial account data. But it's a reminder: cyber threats are real. Check your insurance company's data security policies. Ask how they protect your information.
Comments