Skip to content

NAIC PeopleSoft incident disrupts insurer designations

Summary

NAIC detected unauthorized access to its PeopleSoft environment on June 11, 2026, after exploitation of a zero-day vulnerability. Data was acquired and published, while suspended credit-rating feeds disrupted insurer investment designations and online invoice payments remained unavailable in the latest official update.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Impacted location

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Not Ransomware
Attribution:
Medium

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Data extortion

    Threats to publish or sell stolen data without evidence of encryption.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Vulnerability exploitation

    Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data publication or leak

    Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.

Operational impacts

Extortion indicators

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Full data publication

    The actor published or released a substantial or complete set of allegedly stolen victim data.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the National Association of Insurance Commissioners experienced unauthorized access involving its Oracle PeopleSoft environment. NAIC’s security update says it detected the access June 11, 2026, and that information enabling temporary access to certain storage areas was used to acquire data later published.

Oracle’s CVE-2026-35273 advisory describes an unauthenticated, remotely exploitable PeopleSoft PeopleTools vulnerability that can permit remote code execution. NAIC attributed its incident to exploitation of the PeopleSoft zero-day and said it was part of a broader campaign.

Operational significance

Some credit-rating providers paused rating-symbol feeds after notification. Beginning June 18, NAIC suspended assigning and publishing designations derived from certain public or private ratings in AVS+. Its July 8 update supplied a second-quarter reporting workaround using June 17 data but did not announce restoration of the regular designation process. Online PeopleSoft invoice payment also remained unavailable in the latest operational update.

NAIC said most operations had returned to normal and that major state regulatory platforms were unaffected. The confirmed residual effects were therefore narrower designation and payment exceptions rather than an organization-wide outage.

Current status

July 8 is the latest date on which an authoritative source documented unresolved operational exceptions. No newer source showed continuing disruption or positive restoration. Eighteen calendar days had elapsed by July 26, so the incident is presumed active under the operational lifecycle. Later data-publication, extortion and investigative developments do not extend the operational clock unless they document continuing operations.

Confidence and uncertainty

Confidence is high in vulnerability exploitation, unauthorized access, data acquisition, publication and operational disruption because NAIC confirmed those facts. Confidence is medium in ShinyHunters attribution because the group claimed the incident and independent reporting connected the claim, but NAIC did not name the actor. The evidence supports data-theft extortion rather than ransomware encryption.

Analytic gaps

The public record does not establish the intrusion start, dwell time, full affected-host inventory, lateral movement, complete published-data contents, ransom amount, negotiation history or conclusive attribution. Restoration dates for CRP-based designation processing and PeopleSoft invoice payment remain unknown.

Threat actor and claim

Listed as: NAIC.orgSource: ransomware.livePublished: Discovered:

Claim details

ShinyHunters claimed on its leak site that it obtained and published more than 3.1 TB of NAIC.org data. NAIC confirmed publication by the responsible party but did not publicly name the group or validate the claimed volume.

Screenshot documenting ShinyHunters claim

Organizations involved

Impacted location

Sources

Missouri-based NAIC incident disrupts insurer investment designations
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

NAIC said a PeopleSoft security incident left insurer investment designations suspended and online invoice payments unavailable; it also said unauthorized access reached data storage areas and that ShinyHunters claimed more than 3.1 TB of data.

Security Incident Update
National Association of Insurance CommissionersPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

NAIC says it detected unauthorized PeopleSoft access June 11, confirmed data acquisition and publication, and dated the CRP-based FE/PLR designation pause to June 18. Its latest dated update, July 8, supplied a second-quarter workaround using June 17 rating data but did not announce restoration; online PeopleSoft invoice payment had also remained unavailable.

Oracle Security Alert Advisory - CVE-2026-35273
OraclePublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Oracle’s June 10 alert says CVE-2026-35273 affects PeopleSoft Enterprise PeopleTools 8.61 and 8.62, is remotely exploitable over HTTP without authentication, has a CVSS 3.1 score of 9.8, and can result in remote code execution.

NAIC says public data stolen in ShinyHunters' PeopleSoft breach
BleepingComputerBy Bill ToulasPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

BleepingComputer reported that ShinyHunters claimed the NAIC intrusion and published data after NAIC refused a ransom. The group revised its claim to 3.1 TB across about 105,000 files and acknowledged that an earlier inventory was exaggerated through AI hallucinations; NAIC disputed the broader system claims and reported no evidence of PII or financial-data exposure.