NAIC Confirms Cyberattack Linked to Oracle PeopleSoft Zero-Day as Insurance Systems Face Disruptions

NAIC has confirmed a cyberattack exploiting an Oracle PeopleSoft zero-day, disrupting insurer investment designation services following earlier claims by ShinyHunters.
NAIC logo displayed against a purple abstract background, used as the featured image for BreachNews coverage of the organization’s confirmed cyberattack linked to the Oracle PeopleSoft zero-day.
NAIC has confirmed a cyberattack involving exploitation of an Oracle PeopleSoft zero-day after previously appearing on the ShinyHunters leak site. The incident temporarily disrupted several insurance regulatory services while the organization continues its investigation.

The National Association of Insurance Commissioners (NAIC) has confirmed it suffered a cyberattack after attackers exploited a zero-day vulnerability affecting Oracle PeopleSoft, with the incident disrupting key insurance regulatory services and following earlier extortion claims by the ShinyHunters ransomware group.

NAIC said it detected unauthorized access to part of its environment on June 11 after attackers exploited the vulnerability to access its PeopleSoft environment before moving into certain internal data storage locations. The organization said it immediately contained the intrusion, notified law enforcement, and engaged third-party cybersecurity specialists to investigate.

The confirmation follows BreachNews’ June 19 reporting, when ShinyHunters added NAIC to its leak site and claimed to have stolen approximately 3.1 TB of data. At the time, the allegations could not be independently verified.

Operations impacted following intrusion

While NAIC said most of its services have now returned to normal, the incident continues to affect several operational systems.

The organization confirmed that insurer investment designation processing remains suspended after multiple credit rating agencies temporarily halted the transfer of information used in the designation process. Online invoice payments through PeopleSoft also remain unavailable while remediation work continues.

NAIC emphasized that the attack did not compromise state insurance department systems and said independent investigators determined that several major regulatory platforms, including insurer filing, licensing, and reporting systems, were not affected.

Investigation details emerge

According to NAIC, attackers exploited an Oracle PeopleSoft zero-day vulnerability that has been linked to a wider campaign targeting organizations running the enterprise software platform. The organization said the access path has since been blocked.

Its investigation found that the attackers obtained publicly available statutory financial reporting information, insurer investment credit rating data, and certain technical information including outdated logs and configuration files.

NAIC stated it has found no evidence that personal information, banking information, or payment card data was accessed during the incident.

Although NAIC did not identify the attackers, the timeline closely aligns with claims made by ShinyHunters, which listed the organization on its extortion site shortly after the incident became public. The group alleged it had stolen more than 3.1 TB of data, including insurer regulatory filings, financial statements, customer records, cloud infrastructure logs, SQL scripts, and internal documentation. BreachNews has not independently verified the authenticity or scope of those claims.

ShinyHunters claims data has now been leaked

Since NAIC confirmed the cyberattack, ShinyHunters has updated its leak site to claim the allegedly stolen data has now been published. The group also revised its original description of the purported breach, stating that an earlier assessment had overstated the scope due to what it described as an analytical error and AI-generated misinterpretation.

According to the updated listing, the group now claims the published dataset totals approximately 3.1TB across more than 105,000 files originating from NAIC’s INSData statutory filing platform and Vision credit rating feed server. BreachNews has not independently verified the authenticity of the alleged data or whether it originated from NAIC systems.

ShinyHunters leak site showing an updated entry for the National Association of Insurance Commissioners (NAIC), claiming approximately 3.1TB of data across more than 105,000 files has been published following revised analysis.
ShinyHunters updated its NAIC leak site listing, claiming the allegedly stolen dataset totals about 3.1TB across 105,000 files after revising an earlier description of the purported compromise.

Part of a broader Oracle campaign

The incident forms part of a broader campaign targeting Oracle PeopleSoft deployments. As previously reported by BreachNews, attackers began exploiting the zero-day before Oracle released emergency security updates, with security researchers linking the activity to compromises affecting more than 100 organizations worldwide.

The NAIC incident represents one of the highest-profile confirmed victims tied to the campaign and highlights how vulnerabilities in widely deployed enterprise software can disrupt critical services supporting regulated industries. Although the organization said core regulatory systems remain operational, the ongoing suspension of insurer investment designation processing demonstrates the operational impact such attacks can have beyond the initial network compromise.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map