The National Association of Insurance Commissioners said hackers exploited a zero day vulnerability in Oracle’s PeopleSoft application to exfiltrate confidential financial data from its systems.

The National Association of Insurance Commissioners said hackers exploited a zero day vulnerability in Oracle’s PeopleSoft application to exfiltrate confidential financial data from its systems.
The Association, which provides expertise, data, and analysis for insurance commissioners to effectively regulate the industry and protect consumers, said it discovered on June 11 that malicious actors had gained access to a portion of its IT environment.
An investigation into the unauthorised access revealed that hackers who hijacked Oracle’s PeopleSoft application had obtained information they needed to gain temporary access to NAIC’s IT environment. The unauthorised access was promptly removed and the insurance advisory body engaged cyber security specialists and the FBI to investigate the incident.
"The incident resulted from a broad campaign to exploit a vulnerability in PeopleSoft that was unknown to the developer or software users at the time, otherwise known as a “zero-day vulnerability,” which affected multiple organisations. The NAIC uses PeopleSoft primarily for internal financial reporting purposes," NAIC said.
NAIC’s announcement followed not long after the ShinyHunters extortion gang claimed that it compromised Oracle PeopleSoft installations to infiltrate the networks of over 100 organisations worldwide. The supply chain attack was particularly severe because PeopleSoft is used by organisations worldwide to manage human resources, finance, payroll, supply chain, procurement and administrative tasks.
According to NAIC, data accessed and exfiltrated by the hackers included financial reporting information, credit rating agency data, including rating determinations of insurer investments, and additional data such as routine technical information, such as outdated logs or configuration information. The hackers had published the stolen information.
NAIC added that the stolen information did not include any personally identifiable information or payment and financial account information and the cyber incident did not impact any internal systems.
"In conjunction with NAIC senior management, our outside cybersecurity experts have confirmed that affected systems have been remediated, and we have taken additional steps to strengthen our defenses with their partnership," the institution said.
"The NAIC is aware data taken from our environment during the security incident was published online by the group responsible. We are actively working with an external cybersecurity partner to compare the scope and type of data the group posted with our own analysis."
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543