Data breach
NAIC.org
- Records
- 82,798
- Breach date
- 18 June 2026Estimated
- Added
- 29 September 2026
What was exposed
5 types of data · 1 puts you at serious risk
- Names82,798
- Social security numbers32,133
- Email addresses20,678
- Phone numbers12,398
- Street addresses12,301
About this breach
The National Association of Insurance Commissioners (NAIC), the Kansas City-based organization that supports state insurance regulators, confirmed it was hit in a hacking campaign that exploited a zero-day vulnerability in Oracle PeopleSoft. The extortion group ShinyHunters claimed responsibility and added the NAIC to its leak site on June 18, 2026. According to our investigation team, the indexed data associated with this listing spans roughly 82,800 records and includes names, Social Security numbers, email addresses, phone numbers, and street addresses. The NAIC's own investigation has disputed the scope of what was taken, and the discrepancy between the two accounts remains unresolved.
Breach Timeline
June 10, 2026: Oracle published a security advisory and patches for CVE-2026-35273, a critical PeopleSoft vulnerability exploitable remotely without authentication, after the flaw had already been actively exploited.
June 11, 2026: The NAIC detected unauthorized access to its PeopleSoft system, used primarily for internal financial reporting. Google threat researchers the same day attributed the broader campaign, which ran from May 27 to June 9, to ShinyHunters.
June 17, 2026: The NAIC posted its first public statement about the incident.
June 18, 2026: ShinyHunters listed the NAIC on its data-leak blog, claiming more than 3.1 terabytes of data across over 105,000 files.
June 25, 2026: The NAIC confirmed the stolen data had been published online and said it was comparing the posted material with its own analysis.
August 17, 2026: The NAIC resumed publishing designations on its Automated Valuation Service platform as systems came back online, per Insurance Business.
What Information Was Compromised?
Our analysis found the following data types in this breach: 82,798 names, 32,133 Social Security numbers, 20,678 email addresses, 12,398 phone numbers, and 12,301 street addresses.
The NAIC has publicly stated a different picture. According to SecurityWeek, the organization said the hackers accessed publicly available statutory financial reporting information, credit rating agency data including rating determinations of insurer investments, and routine technical information such as outdated logs and configuration data. The NAIC said personally identifiable information, payment information, and financial account information were not compromised, and that no employee data, policyholder information, or producer data was accessed. ShinyHunters itself later revised its claims, blaming an AI-generated misinterpretation for exaggerating what it stole, according to BankInfoSecurity.
Not every individual is affected by every type of data listed here.
Because the NAIC's assessment and the indexed data do not fully align, the true exposure for any specific individual remains uncertain.
What Are the Potential Risks for Affected Individuals?
If Social Security numbers, names, addresses, and phone numbers were in fact taken, they can be combined for identity theft: opening accounts in someone else's name, filing fraudulent tax returns, or building convincing phishing messages that reference real personal details. Emails paired with names can support targeted scams that appear credible because they cite accurate information. People whose data appears in this listing should treat unexpected calls, texts, or emails referencing their insurance or financial records with caution, even if the NAIC maintains that no personal information was accessed.
What Is NAIC.org Doing in Response?
The NAIC engaged outside counsel and cybersecurity experts, contacted the FBI and its cyber insurance carrier, and said the incident was promptly contained after detection on June 11. Cybersecurity experts remediated the affected systems, and the organization said state insurance departments' systems were not affected. The breach disrupted the Securities Valuation Office's assignment of investment designations beginning June 18, prompting the NAIC to temporarily suspend new designations and later approve deadline extensions. The NAIC said it would compare the leaked data against its own systems and has committed to transparency as its assessment proceeds.
What Should You Do If You Were Affected?
Place a free fraud alert or credit freeze with the three major credit bureaus.
Monitor your credit reports and financial accounts for unfamiliar activity.
Watch for phishing messages that reference your name, address, or insurance details and avoid clicking links in unsolicited messages.
If you believe your Social Security number was misused, file a report with the FTC at IdentityTheft.gov.
In the news
- Insurance Journal: NAIC Victim of Cyber Incident Via PeopleSoft Systeminsurancejournal.com (opens in a new tab)
- Insurance Journal: NAIC Says Data Taken in Hack Has Been Published Onlineinsurancejournal.com (opens in a new tab)
- SecurityWeek: Insurance Regulators Group NAIC Hit in Oracle PeopleSoft Hacksecurityweek.com (opens in a new tab)
- BankInfoSecurity: Nissan Traces Data Breach to PeopleSoft Zero-Day Exploitbankinfosecurity.com (opens in a new tab)
