Cybersecuritydive NAIC Confirms Data Breach Linked to Oracle PeopleSoft Vulnerability
Article Content
- •The NAIC suffered a breach due to a zero-day vulnerability in Oracle PeopleSoft.
- •Sensitive data, including unpublished credit ratings, was accessed and published by hackers.
- •Multiple credit rating agencies have suspended data feeds to NAIC following the incident.
The National Association of Insurance Commissioners (NAIC) reported a cybersecurity breach affecting its systems, detected on June 11, 2026. The breach was linked to a zero-day vulnerability in Oracle PeopleSoft, tracked as CVE-2026-35273. Hackers exploited this flaw to access and publish sensitive data, including unpublished credit ratings information from KBRA and other agencies. The NAIC confirmed that no personally identifiable information or financial account data was compromised. Several credit rating agencies, including Moody's and Fitch Ratings, have suspended data feeds to NAIC as a precaution. The breach has impacted the NAIC's ability to assign designations to insurer investments. The FBI is involved in the ongoing investigation, and the NAIC has engaged cybersecurity experts to enhance its defenses. Operations have mostly returned to normal, except for some online services still being unavailable.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ShinyHunters, KBRA and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Hack Exposes Sensitive FBI Employee Data On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security…
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…