ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hackers publish millions of files stolen from US insurance regulator NAIC

A cybercriminal group released a vast cache of data taken from the agency that oversees insurance regulation across the country, marking one of the year’s most significant breaches in the financial services sector.

Linked InXFacebook
bookmark_borderSave to Library

ShinyHunters, a hacking group, published approximately 3.1 terabytes of data allegedly stolen from the National Association of Insurance Commissioners after the organization failed to meet an extortion deadline. The stolen material includes hundreds of thousands of regulatory documents filed by insurance companies nationwide, financial data from credit rating agencies, and internal infrastructure files from NAIC’s computer systems.


The breach, which originated in late May, exploited a critical security flaw in Oracle PeopleSoft software. The vulnerability, rated 9.8 on a 10-point severity scale, required only network access to compromise and allowed attackers to obtain login credentials that granted entry to internal storage systems. Oracle did not issue a security advisory until June 10, leaving a two-week window during which the same flaw compromised more than 100 organizations globally. NAIC detected the breach on June 11 and engaged the FBI and outside cybersecurity contractors.


ShinyHunters set a June 22 deadline for contact and threatened to release the stolen material if NAIC did not respond to extortion demands. The organization did not engage with the threat, and the data was published this week.


The alleged dataset encompasses more than 264,000 regulatory filing documents from property, casualty, health and life insurers dating from 2017 through 2024; approximately 45,000 files from credit rating agencies including Moody’s, Fitch, and Standard and Poor’s; insurer financial statements; some 2,000 customer records containing names and email addresses; production infrastructure logs and configuration files; and database scripts with stored credentials linked to live systems.


NAIC’s investigation found no evidence that core operational systems were breached and concluded that no personal identifying information or payment data were accessed. The organization confirmed that stolen materials include statutory financial reports, credit rating information, and outdated system logs. A complete assessment would require at least several weeks, NAIC stated.


The breach carries implications beyond a single company’s operations. As the coordinating body for U.S. insurance regulation, NAIC holds data from thousands of licensed insurers and maintains connections to all 50 state insurance departments. The theft of infrastructure files and credentials gives sophisticated attackers a detailed map of NAIC’s computer environment and data flows, security researchers noted, enabling potential follow-on attacks months after the initial compromise.


The NAIC attack was among several breaches this month involving the same Oracle PeopleSoft vulnerability. ShinyHunters also claimed responsibility for incidents affecting Amazon One Medical, the Council of Europe, Kodak, and dental insurer DentaQuest.


The FBI reported that U.S. cyber losses reached nearly $21 billion in 2025. Regulatory bodies and government organizations rank among the top three most targeted sectors globally, according to the FBI’s 2026 Internet Crime Report. The logic is straightforward: compromising a single regulatory agency creates exposure across every organization that reports to it.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543