The National Association of Insurance Commissioners (NAIC), a US organisation supporting the state-based insurance regulatory system, detected unauthorized access to part of its environment on June 11, 2026. The intrusion used an Oracle PeopleSoft zero-day vulnerability; the NAIC primarily uses PeopleSoft for internal financial reporting.
The incident matters because of the way its public record changed. On June 18 and 23, the NAIC said it could not confirm that the data claimed by the attackers had been published. On June 25, it acknowledged that a dataset had been posted online. Its June 26 and July 2 updates described the known content while maintaining a distinction between the confirmed scope and the volume claimed by the group responsible.
What the NAIC confirmed
The first important date is June 11, when the NAIC identified access to a portion of its environment through PeopleSoft. According to its account, the intruder obtained information in PeopleSoft that enabled temporary access to certain storage areas. That path was later blocked and remediated, and the NAIC said the incident was contained.
The NAIC also clarified what the incident did not establish. State insurance departments’ systems were not affected. The regulatory filing systems named in the claims — SERFF, OPTins, UCAA, EDP and RDC — were not taken according to the experts engaged by the NAIC. The same update said that, based on the findings available at the time, employee personal data, electronic funds transfer information, risk-based capital data, policyholder information, producer data and event-registration payments had not been accessed.
A vulnerability inside a broader campaign
Oracle published a Security Alert for CVE-2026-35273 on June 10. It describes a remotely exploitable PeopleSoft PeopleTools vulnerability that requires no authentication and may lead to remote code execution, affecting versions 8.61 and 8.62 among the supported releases. Those details describe the software exposure; they do not by themselves prove that a particular organisation was compromised.
Mandiant and Google Threat Intelligence documented the wider context: an active intrusion and extortion campaign against PeopleSoft infrastructure, observed from May 27 through June 9 and attributed to UNC6240, also tracked as ShinyHunters. The researchers said they notified more than 100 organisations whose IP addresses appeared to match potentially vulnerable endpoints, mostly in the United States and higher education. The NAIC therefore fits into a multi-organisation campaign; that context does not validate the volume claimed for the NAIC or every claim made by the group.
InsData: a data repository, not proof of access to every system
The scope described by the NAIC concerns a repository supporting InsData, its public portal for insurance-company financial statements and statutory reporting information. The annual and quarterly statements in question were already available for purchase through InsData, state websites or resellers.
The NAIC also said that rating-agency data, including rating determinations for insurer investments, was among the data accessed or acquired. It excluded the agencies’ investment-rationale reports. Additional storage areas may have contained routine technical information such as outdated logs or configuration data.
That distinction matters. A repository feeding a public portal can still contain sensitive working data and trusted paths, but its compromise does not automatically mean that private insurer data or policyholder and producer data was extracted. As of July 2, the NAIC said there was no evidence that those personal, banking or payment categories had been accessed or released.
Why the lack of confirmation mattered
On June 18 and again on June 23, the NAIC separated three levels of information: unauthorized access was confirmed; the group’s claim to have obtained data was public; publication of data from the NAIC environment was not confirmed. That wording was cautious, but it avoided turning an extortion statement into an inventory of stolen data.
The position changed on June 25, when the NAIC reported that a dataset had been posted and brought in an external partner to compare it with its internal analysis. Insurance Journal reported the change and the temporary suspension of some rating-agency feeds. The July 2 update then said that an outside data consultant still needed to validate the posted dataset and that the process would take several weeks.
The communication lesson is practical: publish the detected fact quickly, label what remains uncertain, correct the timeline when new evidence arrives and do not repeat a claimed volume as an established measure. Organisations covering the incident should date each statement and preserve the difference between “access,” “data accessed or acquired” and “data published.”
What PeopleSoft teams should verify
Organisations running PeopleSoft should treat Oracle’s June 10 alert as a priority action. Confirm the deployed version, apply the appropriate patch or mitigation and check exposure of Environment Management Hub and its related endpoints.
Remediation should not stop at the PeopleSoft server. The NAIC case shows the risk of an internal system that can obtain access material for other storage areas. Teams should review service accounts, integration secrets, read and write permissions, access logs and outbound connections. If abnormal access is found, revoke and replace the relevant secrets, then preserve evidence for the investigation.
Business owners should also prepare communication that separates operational impact from impact on people. At the NAIC, the designation process for some investments and online invoice payments through PeopleSoft experienced temporary effects, while regulatory filing systems were reported as operating normally. That level of detail prevents a rating-feed interruption from being mistaken for a personal-data breach.
The Soclyde connection
Soclyde does not protect the NAIC’s PeopleSoft environment and cannot determine what data was published. Its role is narrower: helping teams reduce reused trust paths around business applications, generate unique secrets for service accounts and keep those secrets in an encrypted vault under local control.
When an internal system is a starting point toward a repository, separating secrets and quickly identifying which accounts need revocation can reduce propagation risk. This complements software patching, log monitoring and incident investigation; it does not replace them.
Takeaway
The NAIC incident is confirmed: unauthorized access through a PeopleSoft vulnerability reached part of the environment and a repository supporting InsData. The campaign was broader than the NAIC, but the 3.1 TB volume claimed by the attackers is not a scope confirmed by the NAIC. Responsible communication means following dated updates, separating publication from claims and not extrapolating to personal data that the available evidence excludes.
To structure secret rotation for internal applications, read our secure password generator guide or contact Soclyde.



