Last Update: 09/22/2026 at 11:34 PM EST
NAIC breach linked to Oracle PeopleSoft zero-day
Coverage from Yahoo Tech, SecurityWeek, and others

The National Association of Insurance Commissioners confirmed that attackers exploited an Oracle PeopleSoft zero-day, obtained credentials, and moved laterally into internal storage.
NAIC said the accessed data primarily consisted of publicly available regulatory and credit-rating information, outdated logs, and configuration files, with no evidence that personal, banking, or payment information was compromised. ShinyHunters claimed a substantially larger theft and published data online, leaving the final scope under forensic review while the incident caused temporary disruption to some insurance data operations.
Looking Back
4 Day Timeline
Jun 26
Jun 27
Jun 28
Jun 29
All Articles5 articles
Additional
6/26/2026 • Cybersecurity Tech (Privacy-Relevant) • General
6/26/2026 • Data Breaches & Exposure Events • General
6/29/2026 • Cybersecurity (Privacy-Relevant) • General
6/29/2026 • Data Breaches & Exposure Events • General
6/26/2026 • Data Breaches & Exposure Events • General
