NAIC PeopleSoft incident disrupts insurer designations
Summary
NAIC detected unauthorized access to its PeopleSoft environment on June 11, 2026, after exploitation of a zero-day vulnerability. Data was acquired and published, while suspended credit-rating feeds disrupted insurer investment designations and online invoice payments remained unavailable in the latest official update.
Key facts
Timeline
-
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Impacted location
Primary victim organization
Organization types
Critical infrastructure sector
DysruptionHub coverage
Incident characteristics
Assessments
- Status:
- Presumed Active
- Incident confidence:
- High
- Ransomware:
- Not Ransomware
- Attribution:
- Medium
DD-CIT classification
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Attack mechanisms
-
Data extortion
Threats to publish or sell stolen data without evidence of encryption.
-
Unauthorized access
Unauthorized access to systems, accounts, networks, or data.
-
Vulnerability exploitation
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Data impacts
-
Data theft or exfiltration
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
-
Data publication or leak
Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.
Operational impacts
-
Payment processing disruption
The organization could not process, receive, issue, reconcile, or record payments normally.
-
Transaction processing disruption
Business, financial, customer, administrative, or operational transactions could not be completed normally.
-
Downstream organization impact
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Extortion indicators
-
Public leak threat
The actor explicitly threatened to publish or publicly release victim data or incident details.
-
Ransom demand
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
-
Data-theft extortion
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
-
Leak-site listing
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
-
Full data publication
The actor published or released a substantial or complete set of allegedly stolen victim data.
Incident narrative
Analyst assessment
DysruptionHub assesses with high confidence that the National Association of Insurance Commissioners experienced unauthorized access involving its Oracle PeopleSoft environment. NAIC’s security update says it detected the access June 11, 2026, and that information enabling temporary access to certain storage areas was used to acquire data later published.
Oracle’s CVE-2026-35273 advisory describes an unauthenticated, remotely exploitable PeopleSoft PeopleTools vulnerability that can permit remote code execution. NAIC attributed its incident to exploitation of the PeopleSoft zero-day and said it was part of a broader campaign.
Operational significance
Some credit-rating providers paused rating-symbol feeds after notification. Beginning June 18, NAIC suspended assigning and publishing designations derived from certain public or private ratings in AVS+. Its July 8 update supplied a second-quarter reporting workaround using June 17 data but did not announce restoration of the regular designation process. Online PeopleSoft invoice payment also remained unavailable in the latest operational update.
NAIC said most operations had returned to normal and that major state regulatory platforms were unaffected. The confirmed residual effects were therefore narrower designation and payment exceptions rather than an organization-wide outage.
Current status
July 8 is the latest date on which an authoritative source documented unresolved operational exceptions. No newer source showed continuing disruption or positive restoration. Eighteen calendar days had elapsed by July 26, so the incident is presumed active under the operational lifecycle. Later data-publication, extortion and investigative developments do not extend the operational clock unless they document continuing operations.
Confidence and uncertainty
Confidence is high in vulnerability exploitation, unauthorized access, data acquisition, publication and operational disruption because NAIC confirmed those facts. Confidence is medium in ShinyHunters attribution because the group claimed the incident and independent reporting connected the claim, but NAIC did not name the actor. The evidence supports data-theft extortion rather than ransomware encryption.
Analytic gaps
The public record does not establish the intrusion start, dwell time, full affected-host inventory, lateral movement, complete published-data contents, ransom amount, negotiation history or conclusive attribution. Restoration dates for CRP-based designation processing and PeopleSoft invoice payment remain unknown.
Threat actor and claim
Claim details
ShinyHunters claimed on its leak site that it obtained and published more than 3.1 TB of NAIC.org data. NAIC confirmed publication by the responsible party but did not publicly name the group or validate the claimed volume.

Organizations involved
National Association of Insurance Commissioners

Locations
Organization type
Critical infrastructure
Impacted location
Kansas City, Jackson County, Missouri, USA
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
NAIC said a PeopleSoft security incident left insurer investment designations suspended and online invoice payments unavailable; it also said unauthorized access reached data storage areas and that ShinyHunters claimed more than 3.1 TB of data.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
NAIC says it detected unauthorized PeopleSoft access June 11, confirmed data acquisition and publication, and dated the CRP-based FE/PLR designation pause to June 18. Its latest dated update, July 8, supplied a second-quarter workaround using June 17 rating data but did not announce restoration; online PeopleSoft invoice payment had also remained unavailable.
- Type: Official Statement
- Stance: Confirm
- Platform: Website
- Medium: Web Page
- Confidence: High
Oracle’s June 10 alert says CVE-2026-35273 affects PeopleSoft Enterprise PeopleTools 8.61 and 8.62, is remotely exploitable over HTTP without authentication, has a CVSS 3.1 score of 9.8, and can result in remote code execution.
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
BleepingComputer reported that ShinyHunters claimed the NAIC intrusion and published data after NAIC refused a ransom. The group revised its claim to 3.1 TB across about 105,000 files and acknowledged that an earlier inventory was exaggerated through AI hallucinations; NAIC disputed the broader system claims and reported no evidence of PII or financial-data exposure.