NAIC confirms breach as ShinyHunters dumps 3.1TB tied to national insurance systems


The National Association of Insurance Commissioners (NAIC) on Thursday confirmed data was stolen during a recent Oracle zero-day attack earlier this month – all as the notorious ShinyHunters dumps a 3.1TB cache it says is tied to the regulatory body's systems used across the US insurance industry.

Key takeaways:

In a breach update on its website, NAIC said it was aware that the “data taken was published online by the group responsible,” without naming the notorious extortionists directly.

ADVERTISEMENT

The “security incident” – first discovered by NAIC on June 11th – was linked to a recently disclosed zero-day vulnerability affecting Oracle's PeopleSoft software, a cloud-based business management platform the organization said it primarily uses for internal financial reporting purposes.

National Association of Insurance Commissioners breach notice
NAIC, which first reported the breach on June 17th, says stolen data was posted online by a threat group. naic.org

Why the breach matters

NAIC plays a central role in US insurance regulation, collecting insurer data and operating key systems used by regulators and insurance companies nationwide.

Its data and analysis are used to determine everything from the financial health and credit ratings of major US insurance companies to the regulation of insurance products, pricing, and oversight – meaning a breach of its systems could have a ripple effect on the infrastructure powering the entire US insurance industry.

Falling under the US financial services sector, the federal government classifies the insurance industry as critical infrastructure.

Insurance hack
The insurance industry is classified as US critical infrastructure. Image by Golden Dayz | Shutterstock

NAIC said no personally identifiable information (PII) or payment information was accessed – including credit card or banking information – and that state insurance departments’ systems were unaffected.

ADVERTISEMENT

What data was compromised?

Oracle's PeopleSoft is used by more than 10,000 enterprises worldwide.

The ShinyHunters mass-hacking campaign ran from May 27th until an emergency patch was released on June 10th, successfully targeting over 100 organizations and 300 individual instances, according to Google Mandiant.

Posting NAIC on its dark leak site Thursday, ShinyHunters said it was amending a previous “overstatement” about the alleged contents of the data dump, claiming it was now providing more accurate details after "human review."

The mistake was apparently “due to an analytical error and an AI-generated misinterpretation of the underlying data," ShinyHunters wrote.

ShinyHunters National Association of Insurance Commissioners
hinyHunters says it revised its analysis of the alleged NAIC data dump. Image by Cybernews

Meanwhile, in its website update, NAIC said investigators found no evidence that core systems were compromised.

NAIC said unaffected systems include its System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), Uniform Certificate of Authority Application (UCAA), Electronic Data Platform (EDP), or Regulatory Data Catalog (RDC).

Additionally, NAIC said the following were not accessed: employee personal data, electronic funds transfer, risk-based capital data, policyholder information, producer data, and event registration payment information.

jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
ADVERTISEMENT

However, files posted by ShinyHunters suggest the alleged 3.1TB dataset could extend far beyond ordinary insurance documents.

The group claims to have stolen the following:

  • More than 264,000 insurer regulatory filing PDFs spanning property, casualty, health, and life insurance companies between 2017 and 2024.
  • Around 2,000 customer and bulk order records containing names, email addresses, and payment transaction identifiers.
  • Approximately 45,000 files from major credit rating agencies, including Moody's, Fitch, S&P, Kroll, DBRS, AM Best, Egan-Jones, and HR Ratings.
  • Statutory annual and quarterly financial statements submitted by insurers.
  • Production AWS infrastructure logs, cloud configuration files, and workload automation data.
  • SQL scripts and what researchers described as stored credentials tied to production environments associated with SERFF, OPTins, and UCAA.

More than just insurance filings

The dataset appears to contain three broad categories of information – insurance industry records, customer information, and technical files that may provide a blueprint of how parts of NAIC's digital infrastructure operate.

The leaked directory listings also reference cloud templates, configuration buckets, application settings, production backups, and automation platforms, suggesting the alleged breach may involve internal infrastructure data in addition to regulatory records.

ShinyHunters National Association of Insurance Commissioners breach index
Directory listings appear to reference cloud configurations and production backups. ShinyHunters leak site. Image by Cybernews

The concern for NAIC is not necessarily the filing documents themselves, as many of the records may already be available through various regulatory channels.

Security experts warn that infrastructure files, configuration data, and production backups could provide the extortion group with a roadmap of the organization's internal environment.

This could expose how systems are connected, how data moves through the network, and potentially provide access to NAIC's sensitive credentials and administrative functions.

ADVERTISEMENT

Has your password leaked?

Enter your password to check if it has leaked. Having a leaked password creates the risk of identity theft, financial damages, and worse!
35,607,543,468
Exposed Passwords
Ad
Protect your personal information from cybercriminals and get 50% off the top-rated password manager
link_title link_title

NAIC said operations have returned to normal, with two exceptions: its online invoice payment via PeopleSoft is now available, and it is awaiting assurances from third-party credit rating providers that its systems are secure.


Unlock more exclusive Cybernews content on YouTube.