What We Know
The NAIC has confirmed it was the victim of a cyber incident tied to its PeopleSoft system and posted security updates acknowledging data were taken. The hacking group ShinyHunters publicly claimed to have stolen a large trove of data—reported in some outlets as about 3.1 TB—and said the intrusion exploited an Oracle/PeopleSoft zero-day vulnerability.
NAIC’s statements characterize the material taken as public data. Multiple reports and a chronology of the NAIC’s communications describe the organization investigating the incident and notifying stakeholders. At least one news account of the investigation says the group is unlikely to have the full scope of data it has claimed, and media coverage has highlighted conflicting technical and volume claims about what was actually exfiltrated.
Source Comparison
Aligned reportingCorroborates
- BleepingComputer↗Reports NAIC said public data were stolen in a PeopleSoft breach tied to ShinyHunters, aligning with NAIC security updates that acknowledged data were taken.
- insurancejournal.com↗Reports NAIC was the victim of a PeopleSoft-related incident and cites the investigation's finding that ShinyHunters is unlikely to have the full scope of data it claimed.
- techradar.com↗Reports NAIC confirmed a breach while ShinyHunters publicly claimed about 3.1 TB stolen and said the intrusion exploited an Oracle/PeopleSoft zero-day, matching the briefing's reported claims.
- tech.yahoo.com↗Summarizes NAIC's confirmation of a data breach and ShinyHunters' claim of 3.1 TB stolen via an Oracle/PeopleSoft zero-day, supporting the briefing's account of volume and exploit claims.
- businessinsurance.com↗Reports NAIC confirmed a June data breach and posted security updates on its site, consistent with the briefing's note that NAIC acknowledged data were taken and was investigating.
Adds context
- insurereinsure.com↗Provides a chronology of NAIC communications about the PeopleSoft incident, supplying detailed timing and content of the organization's updates to stakeholders.
- undercodenews.com↗Highlights conflicting technical and volume claims around the alleged Oracle/PeopleSoft zero-day theft, emphasizing media debate and uncertainty about what was actually exfiltrated.