# Insurance Regulator Disputes Hacker Claims in Major PeopleSoft Breach; ShinyHunters Alleges Massive Data Theft


The National Association of Insurance Commissioners (NAIC), a pivotal U.S. regulatory organization operating in all 50 states, has contradicted claims made by the ShinyHunters extortion gang following a zero-day breach of its Oracle PeopleSoft infrastructure. The discrepancies between what the threat actors claim they stole and what NAIC says was compromised highlight both the sophistication of modern enterprise attacks and the persistent challenges in breach disclosure accuracy.


## The Incident: Exploitation of an Unpatched Vulnerability


On June 11, 2026, NAIC discovered that an unauthorized threat actor had gained access to its IT systems through a zero-day vulnerability (CVE-2026-35273) in its Oracle PeopleSoft server. The organization immediately launched an investigation and notified law enforcement and cybersecurity partners. Within weeks, the ShinyHunters gang emerged publicly to claim responsibility, announcing the breach and subsequently leaking data after NAIC reportedly declined to pay a ransom demand.


ShinyHunters' exploitation of this PeopleSoft zero-day represents part of a broader campaign targeting over 100 organizations across multiple sectors. The group has weaponized the same vulnerability against cloud-hosted and on-premises PeopleSoft instances, with education institutions emerging as particularly targeted victims. Prior to Oracle's public disclosure of the security issue, BleepingComputer had already documented multiple organizations suffering breaches attributed to ShinyHunters' use of this zero-day.


## Background: Oracle PeopleSoft Under Siege


Oracle PeopleSoft remains a widely deployed enterprise resource planning (ERP) system, particularly among large organizations including educational institutions, financial services providers, and government agencies. The platform's prevalence in critical infrastructure makes any zero-day vulnerability within it a matter of significant concern to the broader cybersecurity community.


Key timeline of events:


  • June 11, 2026: NAIC identifies unauthorized access to PeopleSoft systems
  • June 25, 2026: ShinyHunters publicly announces breach and data theft
  • June 29, 2026: NAIC responds with detailed contradictions to threat actor claims
  • Ongoing: Oracle and affected organizations work to patch and remediate vulnerable instances

  • The zero-day vulnerability (CVE-2026-35273) affected both cloud-based and on-premises deployments, expanding the attack surface significantly. Organizations running either configuration faced potential compromise if systems remained unpatched during the window of active exploitation.


    ## Disputed Claims: A Tale of Two Breach Narratives


    The NAIC breach illustrates a growing problem in breach disclosure: conflicting accounts of what was actually stolen. ShinyHunters initially claimed they had compromised critical insurance regulatory platforms including SERFF (System for Electronic Rate and Form Filing), OPTins (Online Premium Tax for Insurance), and SBS (State-Based Systems)—systems essential to insurance regulation and filing.


    NAIC directly disputed these claims, stating that the threat actors had not successfully compromised these critical regulatory systems. The organization's investigation found:


    | Data Type | NAIC's Assessment | Threat Actor Claims |

    |-----------|------------------|-------------------|

    | PII / Financial Data | No evidence of exposure | Claimed 2,000 customer/order/payment records |

    | Critical Regulatory Systems | Not compromised | Claimed access to SERFF, OPTins, SBS |

    | Credentials | Not accessible to hackers | Claimed stored credentials for production environments |

    | Operational Impact | Limited to temporary data feed suspension | Implied full system compromise |


    However, ShinyHunters subsequently updated their claims, acknowledging that an earlier inventory had been inflated due to "AI hallucinations" when evaluating stolen files. The revised inventory—allegedly reviewed by a human analyst—claims the group stole 3.1 TB of data comprising 105,000 files, including:


  • 264,000 insurer regulatory filing PDFs (2017–2024)
  • 45,000 rating agency data files
  • AWS infrastructure configurations
  • Outdated system logs and configuration files
  • 2,000 customer and order records

  • Operational consequences from the breach were documented: credit rating agencies temporarily suspended data feeds to NAIC, and the organization paused investment designation work while systems were remediated.


    ## What Was Actually Compromised?


    According to NAIC's official assessment, the attackers accessed and exfiltrated:


    1. Publicly available statutory financial reports — information already accessible through regulatory channels

    2. Outdated logs and configuration files — valuable for reconnaissance but not containing active secrets

    3. Rating agency data — historical information, though potentially sensitive in aggregate

    4. No evidence of personally identifiable information (PII), active financial records, or direct access to critical regulatory platforms


    The organization emphasized that all affected systems have been remediated and that enhanced defenses have been deployed to prevent future attacks of this nature. This includes patching the zero-day vulnerability and implementing additional monitoring and access controls.


    The discrepancy between initial claims and revised inventory is noteworthy. When ShinyHunters acknowledged using "AI hallucinations," they were referring to automated data classification errors when parsing stolen files. This underscores a meta-concern: threat actors themselves are increasingly deploying AI tools to analyze stolen data, and these tools can be as unreliable as any other automated system.


    ## Broader Context: ShinyHunters' Expanding Campaign


    ShinyHunters has emerged as one of the most active extortion gangs in 2026, distinguishing themselves by:


  • Zero-day exploitation: Unlike many ransomware gangs that rely on known vulnerabilities, ShinyHunters exploited an unpatched PeopleSoft flaw across more than 100 organizations
  • Sector targeting: A focus on education and financial services, areas where organizations often manage sensitive regulatory or institutional data
  • Sustained campaigns: Multiple victims and repeated extortion attempts suggest a disciplined, well-resourced operation
  • Public accountability for claims: The gang's willingness to revise their initial data inventory publicly (albeit while still claiming the data is valuable) indicates awareness of credibility issues

  • Victims previously tied to ShinyHunters include 7-Eleven, Kodak, and Infinite Campus, among others. The diversity of targets—from retail to manufacturing to education—suggests ShinyHunters operates opportunistically, targeting any organization with exploitable PeopleSoft instances and perceived ability to pay ransoms.


    ## Implications for Organizations and Regulators


    The NAIC breach carries several critical implications:


    For Insurance Industry: Insurers and insurance brokers should assume their regulatory filings and related data may have been accessed. While NAIC states that critical systems were not compromised, organizations should verify their own defenses and audit access logs during the compromise window.


    For Enterprise Organizations: Any organization running Oracle PeopleSoft—whether cloud or on-premises—should have immediately applied patches for CVE-2026-35273. The exploit's prevalence across over 100 victims suggests that unpatched systems remain an urgent risk.


    For Regulators: The NAIC incident demonstrates the vulnerability of regulatory infrastructure itself. Insurance commissioners in all 50 states depend on NAIC for data and coordination, making the organization a de facto critical infrastructure asset in the financial services ecosystem.


    For Threat Actor Attribution: The ShinyHunters revision of their claims, while troubling, also provides a baseline for evaluating future breach disclosures from the group. Their willingness to acknowledge AI-driven errors suggests they may face credibility issues that could eventually pressure them toward more honest accounting.


    ---


    ## HackWire Analysis


    The NAIC breach illustrates a critical tension in modern cybersecurity disclosure: the gap between what attackers *claim* and what actually happened. For defenders, this is simultaneously reassuring and alarming.


    The reassuring part: NAIC's investigation found no evidence that critical regulatory systems were compromised, meaning the insurance industry's filing infrastructure remained intact. The stolen data, while sensitive, does not appear to include active financial records or unencrypted credentials that could cascade into secondary attacks.


    The alarming part: ShinyHunters successfully exploited a zero-day affecting over 100 organizations before Oracle could issue a patch. The fact that this group operates with sufficient discipline and resources to weaponize unpatched vulnerabilities across such a large surface area suggests we're facing a tier-one threat actor, not a opportunistic gang.


    The gang's admission that their initial claims contained "AI hallucinations" is particularly revealing. Threat actors are now using large language models to process stolen data at scale, which means their claims may be systematically unreliable. This creates a perverse incentive: organizations cannot trust threat actor disclosures to understand the true scope of compromise, yet regulators and the public rely on those disclosures for transparency.


    Most concerning is the pattern: education, finance, insurance, and retail organizations are being systematically compromised through known but unpatched enterprise software. This suggests a fundamental breakdown in patch management across enterprise environments. Organizations cannot rely on vendors to disclose vulnerabilities before exploitation, and they cannot assume their infrastructure is secure simply because systems "appear" to be functioning normally. The NAIC's successful remediation and NAIC's statements about system integrity are encouraging, but they underscore that detection and response, not prevention, is now the realistic security posture.


    The insurance industry should treat this not as an isolated incident but as a data point in a trend: regulatory infrastructure is increasingly targeted by sophisticated threat actors, and the consequences extend far beyond the immediate victim organization.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)