๐Ÿ‡บ๐Ÿ‡ธ US 30-yr mortgage rate: 6.55% โ€” Bankrate, June 10๐Ÿ‡ฏ๐Ÿ‡ต BOJ June rate hike: 80% market probability โ€” CNBC๐Ÿ‡ฎ๐Ÿ‡ณ India opens insurance to 100% FDI under automatic route๐Ÿ‡บ๐Ÿ‡ธ Fed holds rates at 3.50โ€“3.75% โ€” third consecutive hold๐ŸŒ Global cyber insurance market: $33.4B projected for 2026๐Ÿ‡ฌ๐Ÿ‡ง FCA: Insurance premium finance APRs down 4.1% since 2022๐Ÿ‡ฐ๐Ÿ‡ท DB Insurance completes $1.65B Fortegra acquisition๐Ÿ‡บ๐Ÿ‡ธ Medicaid cuts: CBO estimates 11.8M to lose coverage๐Ÿ‡ฆ๐Ÿ‡บ APRA CPS 230 amendments effective July 1, 2026๐Ÿ‡ฉ๐Ÿ‡ช BaFin launches dedicated cyber insurance reporting class๐Ÿ‡บ๐Ÿ‡ธ US 30-yr mortgage rate: 6.55% โ€” Bankrate, June 10๐Ÿ‡ฏ๐Ÿ‡ต BOJ June rate hike: 80% market probability โ€” CNBC๐Ÿ‡ฎ๐Ÿ‡ณ India opens insurance to 100% FDI under automatic route๐Ÿ‡บ๐Ÿ‡ธ Fed holds rates at 3.50โ€“3.75% โ€” third consecutive hold๐ŸŒ Global cyber insurance market: $33.4B projected for 2026๐Ÿ‡ฌ๐Ÿ‡ง FCA: Insurance premium finance APRs down 4.1% since 2022๐Ÿ‡ฐ๐Ÿ‡ท DB Insurance completes $1.65B Fortegra acquisition๐Ÿ‡บ๐Ÿ‡ธ Medicaid cuts: CBO estimates 11.8M to lose coverage๐Ÿ‡ฆ๐Ÿ‡บ APRA CPS 230 amendments effective July 1, 2026๐Ÿ‡ฉ๐Ÿ‡ช BaFin launches dedicated cyber insurance reporting class
Cybersecurity data breach and regulatory systems hacking - illustrative image
Regulation๐Ÿ‡บ๐Ÿ‡ธUnited States

Insurance Regulator NAIC Confirms Hackers Have Published Stolen Data Online After PeopleSoft Breach

Editorial Deskยทยท5 min read
Verified Story

The US National Association of Insurance Commissioners (NAIC) confirmed on June 25 that data stolen in a cyberattack on its Oracle PeopleSoft system has been published online by the hacking group ShinyHunters. The breach, discovered on June 11, exploited a zero-day vulnerability and is part of a broader campaign affecting more than 100 organizations. The NAIC says no personally identifiable information or payment data was accessed, though credit rating agencies have paused data feeds.

The National Association of Insurance Commissioners (NAIC) โ€” the standards-setting body that supports insurance regulators across all 50 US states โ€” has confirmed that data taken in a cyberattack on its systems has been published online. The NAIC discovered unauthorized access to its Oracle PeopleSoft system on or about June 11, 2026, and issued its first public notice on June 17, with a significant update on June 25 confirming the data leak.

The attack exploited a critical zero-day vulnerability in Oracle PeopleSoft (tracked as CVE-2026-35273), an unauthenticated remote code execution flaw carrying a maximum-severity CVSS score of 9.8 out of 10. Oracle did not publish an advisory until June 10, meaning the flaw was actively exploited for at least 14 days before any official patch existed. The NAIC said the intrusion was part of a broad criminal campaign that struck more than 100 organizations worldwide, attributed to the threat actor group ShinyHunters, which has a record of large-scale data theft and extortion. The group claimed to have obtained 3.1 terabytes of data spanning more than 105,000 files and issued an extortion deadline of June 22.

The NAIC's internal investigation, supported by outside cybersecurity experts and coordinated with the FBI, concluded that the hackers did not gain the scope of access they claimed. Crucially, the NAIC stated that no personally identifiable information, payment data, credit card or banking information, policyholder data, producer data, or risk-based capital data was accessed. The regulator's core regulatory reporting systems โ€” including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), and the Uniform Certificate Authority Application (UCAA) โ€” were confirmed not to have been compromised. The data that was accessed consisted largely of publicly available statutory financial reporting information and credit rating agency determinations.

The incident has nonetheless caused operational disruption: certain credit rating agencies paused their data feeds to the NAIC, prompting the organization to temporarily suspend its assignment of designations to insurer investments โ€” a process that could take months to fully restore. Industry bodies including the National Association of Mutual Insurance Companies (NAMIC) criticized the NAIC's communication timeline, noting the gap between the June 11 discovery and the first public post. The breach underscores the systemic cyber risk facing regulatory bodies, which Microsoft data shows receive more than 600 million identity attacks per day globally.

Key Points

  • 1NAIC confirmed on June 25 that stolen data was published online by hacking group ShinyHunters
  • 2The breach exploited a zero-day PeopleSoft vulnerability (CVE-2026-35273) with a 9.8/10 severity score
  • 3NAIC says no personally identifiable information, payment, or policyholder data was accessed
  • 4Credit rating agencies paused data feeds, suspending NAIC investment designation services
  • 5The attack was part of a broader campaign affecting over 100 organizations worldwide

Why This Matters

The NAIC is the central nervous system of US state-based insurance regulation, handling vast volumes of financial and regulatory data from thousands of insurers. A breach of this body โ€” even one where personal data was reportedly not taken โ€” raises serious concerns about the concentration of sensitive financial data in regulatory systems. For insurers, the temporary suspension of NAIC investment designations creates operational uncertainty. The incident is a stark reminder that regulators themselves are prime cyberattack targets, and that even zero-day vulnerabilities in widely used enterprise software can cascade across an entire industry.

#cyberattack#NAIC#data breach#insurance regulation#ShinyHunters#ransomware
Verified ยท Jun 26, 2026Read Original
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, legal, or insurance advice. Always consult a qualified professional before making financial decisions. PolicyGlobal reports on publicly available information from third-party sources and cannot guarantee the accuracy or completeness of such information.

Related Stories

Daily Intelligence

The PolicyGlobal Daily Brief

Get the top 5 insurance and finance stories every morning, curated and verified by our editorial desk. No spam. Unsubscribe anytime.

Informational newsletter only. Not financial advice. Disclaimer