NAIC Confirms Data Breach Linked to Oracle PeopleSoft Vulnerability

NAIC Confirms Data Breach Linked to Oracle PeopleSoft Vulnerability

First seen 29 Jun 2026, 22:43 UTC Infosecurity-MagazineCybersecuritydivewww.kbra.com 77% similarity 69.0
Share:

Article Content

Browse articles
ThreatCluster

The National Association of Insurance Commissioners (NAIC) reported a cybersecurity breach affecting its systems, detected on June 11, 2026. The breach was linked to a zero-day vulnerability in Oracle PeopleSoft, tracked as CVE-2026-35273. Hackers exploited this flaw to access and publish sensitive data, including unpublished credit ratings information from KBRA and other agencies. The NAIC confirmed that no personally identifiable information or financial account data was compromised. Several credit rating agencies, including Moody's and Fitch Ratings, have suspended data feeds to NAIC as a precaution. The breach has impacted the NAIC's ability to assign designations to insurer investments. The FBI is involved in the ongoing investigation, and the NAIC has engaged cybersecurity experts to enhance its defenses. Operations have mostly returned to normal, except for some online services still being unavailable.

Key Points: • The NAIC suffered a breach due to a zero-day vulnerability in Oracle PeopleSoft. • Sensitive data, including unpublished credit ratings, was accessed and published by hackers. • Multiple credit rating agencies have suspended data feeds to NAIC following the incident.

ThreatCluster AI

Timeline

2026-06-11
NAIC detects cybersecurity breach
The NAIC became aware of unauthorized access to its systems, linked to a zero-day vulnerability in Oracle PeopleSoft.
Infosecurity-Magazine
2026-06-11
CVE-2026-35273 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-18
NAIC publicly discloses breach
The NAIC disclosed the cybersecurity incident to the public, confirming data had been accessed by hackers.
Infosecurity-Magazine
2026-06-26
NAIC confirms data was published
The NAIC informed KBRA that unpublished ratings information had been exported and uploaded to a leak site.
KBRA
2026-06-29
Current status update
The NAIC reported that operations have returned to normal except for online invoice payments, and FBI coordination is ongoing.
Infosecurity-Magazine

Community

Browse all →