CVE Tools

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

BleepingComputerBy Bill Toulas

Reported exploitedOracle PeopleSoftShinyHunters

Our summary

The NAIC says it was compromised by ShinyHunters after the threat group exploited a zero-day in an Oracle PeopleSoft server (CVE-2026-35273). According to NAIC, the attackers obtained mainly already publicly available statutory financial reports, outdated logs, and configuration information, and it reports no evidence that PII or financial data was exposed. The incident still caused disruptions for downstream partners, while ShinyHunters’ leaked-file claims differ from NAIC’s findings and NAIC states affected systems have been remediated.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store