Last Update: 09/22/2026 at 11:34 PM EST

NAIC breach linked to Oracle PeopleSoft zero-day

Coverage from Yahoo Tech, SecurityWeek, and others

NAIC breach linked to Oracle PeopleSoft zero-day topic image

The National Association of Insurance Commissioners confirmed that attackers exploited an Oracle PeopleSoft zero-day, obtained credentials, and moved laterally into internal storage.

NAIC said the accessed data primarily consisted of publicly available regulatory and credit-rating information, outdated logs, and configuration files, with no evidence that personal, banking, or payment information was compromised. ShinyHunters claimed a substantially larger theft and published data online, leaving the final scope under forensic review while the incident caused temporary disruption to some insurance data operations.

Looking Back
4 Day Timeline
Jun 26Jun 27Jun 28Jun 29
All Articles5 articles
Additional5 articles · CI Score below 45
Yahoo Tech
6/26/2026 • Cybersecurity Tech (Privacy-Relevant) • General
SecurityWeek / Eduard Kovacs
6/26/2026 • Data Breaches & Exposure Events • General
Mitchell Williams
6/29/2026 • Cybersecurity (Privacy-Relevant) • General
BleepingComputer / Bill Toulas
6/29/2026 • Data Breaches & Exposure Events • General
TechRadar
6/26/2026 • Data Breaches & Exposure Events • General