Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
The ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization. The post Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack appeared first on SecurityWeek .
AI Analysis
Technical Summary
On June 11, 2026, Oracle published an out-of-band advisory for CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft that permits unauthenticated remote code execution. Exploitation of this vulnerability was observed in the wild shortly after disclosure, with the ShinyHunters cybercrime group conducting a campaign targeting multiple organizations, including the National Association of Insurance Commissioners (NAIC). NAIC confirmed unauthorized access to its systems via this vulnerability, resulting in the theft of approximately 3.1 TB of data, primarily insurer regulatory filing documents and some publicly available financial and technical information. NAIC clarified that sensitive personal and payment information was not compromised, and other related regulatory systems were unaffected. The ShinyHunters group later revised some claims about the extent and nature of the stolen data. This incident highlights active exploitation of a critical PeopleSoft vulnerability shortly after its disclosure.
Potential Impact
The exploitation of CVE-2026-35273 allowed attackers to gain unauthorized access to NAIC systems, resulting in the theft of a large volume of data (over 3.1 TB), including insurer regulatory filing documents and publicly available financial and technical information. However, no personally identifiable information or payment/financial account information was compromised. State insurance departments and various regulatory reporting systems were not affected. The breach potentially exposes sensitive regulatory data, which could impact the confidentiality of insurer filings and related information.
Mitigation Recommendations
Oracle published an out-of-band advisory for CVE-2026-35273 on June 11, 2026, indicating that a fix is available. Organizations using Oracle PeopleSoft should apply the official patch promptly to remediate this vulnerability. Since this is not a cloud service, local patching is required. NAIC and other affected organizations should also review access logs and conduct forensic analysis to ensure no further unauthorized access persists. No vendor advisory states that no action is required or that the issue is already mitigated without patching.
Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
Description
The ShinyHunters extortion group claims to have stolen 3.1 TB of data from the organization. The post Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
On June 11, 2026, Oracle published an out-of-band advisory for CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft that permits unauthenticated remote code execution. Exploitation of this vulnerability was observed in the wild shortly after disclosure, with the ShinyHunters cybercrime group conducting a campaign targeting multiple organizations, including the National Association of Insurance Commissioners (NAIC). NAIC confirmed unauthorized access to its systems via this vulnerability, resulting in the theft of approximately 3.1 TB of data, primarily insurer regulatory filing documents and some publicly available financial and technical information. NAIC clarified that sensitive personal and payment information was not compromised, and other related regulatory systems were unaffected. The ShinyHunters group later revised some claims about the extent and nature of the stolen data. This incident highlights active exploitation of a critical PeopleSoft vulnerability shortly after its disclosure.
Potential Impact
The exploitation of CVE-2026-35273 allowed attackers to gain unauthorized access to NAIC systems, resulting in the theft of a large volume of data (over 3.1 TB), including insurer regulatory filing documents and publicly available financial and technical information. However, no personally identifiable information or payment/financial account information was compromised. State insurance departments and various regulatory reporting systems were not affected. The breach potentially exposes sensitive regulatory data, which could impact the confidentiality of insurer filings and related information.
Mitigation Recommendations
Oracle published an out-of-band advisory for CVE-2026-35273 on June 11, 2026, indicating that a fix is available. Organizations using Oracle PeopleSoft should apply the official patch promptly to remediate this vulnerability. Since this is not a cloud service, local patching is required. NAIC and other affected organizations should also review access logs and conduct forensic analysis to ensure no further unauthorized access persists. No vendor advisory states that no action is required or that the issue is already mitigated without patching.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/insurance-regulators-group-naic-hit-in-oracle-peoplesoft-hack/","fetched":true,"fetchedAt":"2026-06-29T13:51:23.672Z","wordCount":1102}
Threat ID: 6a42785b27e9c79719f438a2
Added to database: 06/29/2026, 13:51:23 UTC
Last enriched: 06/29/2026, 13:51:32 UTC
Last updated: 06/30/2026, 00:08:41 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.