Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hack
Reported exploitedOracle PeopleSoftShinyHuntersOur summary
The National Association of Insurance Commissioners (NAIC) says it was targeted in the recent Oracle PeopleSoft attack chain involving the zero-day vulnerability CVE-2026-35273, which enables unauthenticated remote code execution. NAIC reports unauthorized access discovered on June 11, with attackers obtaining statutory financial reporting and related technical data; however, it states personally identifiable information and payment/financial account details were not compromised. The incident matters because a widely used enterprise platform vulnerability is being actively leveraged by the ShinyHunters group and regulators are now confirming real-world impact.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.