# Insurance Regulator Disputes Hacker Claims in Major PeopleSoft Breach; ShinyHunters Alleges Massive Data Theft
The National Association of Insurance Commissioners (NAIC), a pivotal U.S. regulatory organization operating in all 50 states, has contradicted claims made by the ShinyHunters extortion gang following a zero-day breach of its Oracle PeopleSoft infrastructure. The discrepancies between what the threat actors claim they stole and what NAIC says was compromised highlight both the sophistication of modern enterprise attacks and the persistent challenges in breach disclosure accuracy.
## The Incident: Exploitation of an Unpatched Vulnerability
On June 11, 2026, NAIC discovered that an unauthorized threat actor had gained access to its IT systems through a zero-day vulnerability (CVE-2026-35273) in its Oracle PeopleSoft server. The organization immediately launched an investigation and notified law enforcement and cybersecurity partners. Within weeks, the ShinyHunters gang emerged publicly to claim responsibility, announcing the breach and subsequently leaking data after NAIC reportedly declined to pay a ransom demand.
ShinyHunters' exploitation of this PeopleSoft zero-day represents part of a broader campaign targeting over 100 organizations across multiple sectors. The group has weaponized the same vulnerability against cloud-hosted and on-premises PeopleSoft instances, with education institutions emerging as particularly targeted victims. Prior to Oracle's public disclosure of the security issue, BleepingComputer had already documented multiple organizations suffering breaches attributed to ShinyHunters' use of this zero-day.
## Background: Oracle PeopleSoft Under Siege
Oracle PeopleSoft remains a widely deployed enterprise resource planning (ERP) system, particularly among large organizations including educational institutions, financial services providers, and government agencies. The platform's prevalence in critical infrastructure makes any zero-day vulnerability within it a matter of significant concern to the broader cybersecurity community.
Key timeline of events:
The zero-day vulnerability (CVE-2026-35273) affected both cloud-based and on-premises deployments, expanding the attack surface significantly. Organizations running either configuration faced potential compromise if systems remained unpatched during the window of active exploitation.
## Disputed Claims: A Tale of Two Breach Narratives
The NAIC breach illustrates a growing problem in breach disclosure: conflicting accounts of what was actually stolen. ShinyHunters initially claimed they had compromised critical insurance regulatory platforms including SERFF (System for Electronic Rate and Form Filing), OPTins (Online Premium Tax for Insurance), and SBS (State-Based Systems)—systems essential to insurance regulation and filing.
NAIC directly disputed these claims, stating that the threat actors had not successfully compromised these critical regulatory systems. The organization's investigation found:
| Data Type | NAIC's Assessment | Threat Actor Claims |
|-----------|------------------|-------------------|
| PII / Financial Data | No evidence of exposure | Claimed 2,000 customer/order/payment records |
| Critical Regulatory Systems | Not compromised | Claimed access to SERFF, OPTins, SBS |
| Credentials | Not accessible to hackers | Claimed stored credentials for production environments |
| Operational Impact | Limited to temporary data feed suspension | Implied full system compromise |
However, ShinyHunters subsequently updated their claims, acknowledging that an earlier inventory had been inflated due to "AI hallucinations" when evaluating stolen files. The revised inventory—allegedly reviewed by a human analyst—claims the group stole 3.1 TB of data comprising 105,000 files, including:
Operational consequences from the breach were documented: credit rating agencies temporarily suspended data feeds to NAIC, and the organization paused investment designation work while systems were remediated.
## What Was Actually Compromised?
According to NAIC's official assessment, the attackers accessed and exfiltrated:
1. Publicly available statutory financial reports — information already accessible through regulatory channels
2. Outdated logs and configuration files — valuable for reconnaissance but not containing active secrets
3. Rating agency data — historical information, though potentially sensitive in aggregate
4. No evidence of personally identifiable information (PII), active financial records, or direct access to critical regulatory platforms
The organization emphasized that all affected systems have been remediated and that enhanced defenses have been deployed to prevent future attacks of this nature. This includes patching the zero-day vulnerability and implementing additional monitoring and access controls.
The discrepancy between initial claims and revised inventory is noteworthy. When ShinyHunters acknowledged using "AI hallucinations," they were referring to automated data classification errors when parsing stolen files. This underscores a meta-concern: threat actors themselves are increasingly deploying AI tools to analyze stolen data, and these tools can be as unreliable as any other automated system.
## Broader Context: ShinyHunters' Expanding Campaign
ShinyHunters has emerged as one of the most active extortion gangs in 2026, distinguishing themselves by:
Victims previously tied to ShinyHunters include 7-Eleven, Kodak, and Infinite Campus, among others. The diversity of targets—from retail to manufacturing to education—suggests ShinyHunters operates opportunistically, targeting any organization with exploitable PeopleSoft instances and perceived ability to pay ransoms.
## Implications for Organizations and Regulators
The NAIC breach carries several critical implications:
For Insurance Industry: Insurers and insurance brokers should assume their regulatory filings and related data may have been accessed. While NAIC states that critical systems were not compromised, organizations should verify their own defenses and audit access logs during the compromise window.
For Enterprise Organizations: Any organization running Oracle PeopleSoft—whether cloud or on-premises—should have immediately applied patches for CVE-2026-35273. The exploit's prevalence across over 100 victims suggests that unpatched systems remain an urgent risk.
For Regulators: The NAIC incident demonstrates the vulnerability of regulatory infrastructure itself. Insurance commissioners in all 50 states depend on NAIC for data and coordination, making the organization a de facto critical infrastructure asset in the financial services ecosystem.
For Threat Actor Attribution: The ShinyHunters revision of their claims, while troubling, also provides a baseline for evaluating future breach disclosures from the group. Their willingness to acknowledge AI-driven errors suggests they may face credibility issues that could eventually pressure them toward more honest accounting.
---
## HackWire Analysis
The NAIC breach illustrates a critical tension in modern cybersecurity disclosure: the gap between what attackers *claim* and what actually happened. For defenders, this is simultaneously reassuring and alarming.
The reassuring part: NAIC's investigation found no evidence that critical regulatory systems were compromised, meaning the insurance industry's filing infrastructure remained intact. The stolen data, while sensitive, does not appear to include active financial records or unencrypted credentials that could cascade into secondary attacks.
The alarming part: ShinyHunters successfully exploited a zero-day affecting over 100 organizations before Oracle could issue a patch. The fact that this group operates with sufficient discipline and resources to weaponize unpatched vulnerabilities across such a large surface area suggests we're facing a tier-one threat actor, not a opportunistic gang.
The gang's admission that their initial claims contained "AI hallucinations" is particularly revealing. Threat actors are now using large language models to process stolen data at scale, which means their claims may be systematically unreliable. This creates a perverse incentive: organizations cannot trust threat actor disclosures to understand the true scope of compromise, yet regulators and the public rely on those disclosures for transparency.
Most concerning is the pattern: education, finance, insurance, and retail organizations are being systematically compromised through known but unpatched enterprise software. This suggests a fundamental breakdown in patch management across enterprise environments. Organizations cannot rely on vendors to disclose vulnerabilities before exploitation, and they cannot assume their infrastructure is secure simply because systems "appear" to be functioning normally. The NAIC's successful remediation and NAIC's statements about system integrity are encouraging, but they underscore that detection and response, not prevention, is now the realistic security posture.
The insurance industry should treat this not as an isolated incident but as a data point in a trend: regulatory infrastructure is increasingly targeted by sophisticated threat actors, and the consequences extend far beyond the immediate victim organization.
— HackWire Editorial
---
## Related Coverage