ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

The National Association of Insurance Commissioners said hackers exploited a zero day vulnerability in Oracle’s PeopleSoft application to exfiltrate confidential financial data from its systems.

Linked InXFacebook
bookmark_borderSave to Library

The National Association of Insurance Commissioners said hackers exploited a zero day vulnerability in Oracle’s PeopleSoft application to exfiltrate confidential financial data from its systems.

 

The Association, which provides expertise, data, and analysis for insurance commissioners to effectively regulate the industry and protect consumers, said it discovered on June 11 that malicious actors had gained access to a portion of its IT environment.

 

An investigation into the unauthorised access revealed that hackers who hijacked Oracle’s PeopleSoft application had obtained information they needed to gain temporary access to NAIC’s IT environment. The unauthorised access was promptly removed and the insurance advisory body engaged cyber security specialists and the FBI to investigate the incident.

 

"The incident resulted from a broad campaign to exploit a vulnerability in PeopleSoft that was unknown to the developer or software users at the time, otherwise known as a “zero-day vulnerability,” which affected multiple organisations. The NAIC uses PeopleSoft primarily for internal financial reporting purposes," NAIC said.

 

NAIC’s announcement followed not long after the ShinyHunters extortion gang claimed that it compromised Oracle PeopleSoft installations to infiltrate the networks of over 100 organisations worldwide. The supply chain attack was particularly severe because PeopleSoft is used by organisations worldwide to manage human resources, finance, payroll, supply chain, procurement and administrative tasks.

 

According to NAIC, data accessed and exfiltrated by the hackers included financial reporting information, credit rating agency data, including rating determinations of insurer investments, and additional data such as routine technical information, such as outdated logs or configuration information. The hackers had published the stolen information.

 

NAIC added that the stolen information did not include any personally identifiable information or payment and financial account information and the cyber incident did not impact any internal systems. 

 

"In conjunction with NAIC senior management, our outside cybersecurity experts have confirmed that affected systems have been remediated, and we have taken additional steps to strengthen our defenses with their partnership," the institution said.

 

"The NAIC is aware data taken from our environment during the security incident was published online by the group responsible. We are actively working with an external cybersecurity partner to compare the scope and type of data the group posted with our own analysis."

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543