What We Know
CoolingJust now

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Cooling

What We Know

The NAIC has confirmed it was the victim of a cyber incident tied to its PeopleSoft system and posted security updates acknowledging data were taken. The hacking group ShinyHunters publicly claimed to have stolen a large trove of data—reported in some outlets as about 3.1 TB—and said the intrusion exploited an Oracle/PeopleSoft zero-day vulnerability.

NAIC’s statements characterize the material taken as public data. Multiple reports and a chronology of the NAIC’s communications describe the organization investigating the incident and notifying stakeholders. At least one news account of the investigation says the group is unlikely to have the full scope of data it has claimed, and media coverage has highlighted conflicting technical and volume claims about what was actually exfiltrated.

Source Comparison

Aligned reporting
5 corroborates - 2 adds context - 0 conflicts