NAIC confirms data breach with ShinyHunters claiming 3.1 TB of data stolen in Oracle zero-day attack


  • NAIC confirmed a cyber attack exploiting an Oracle PeopleSoft zero-day in which ShinyHunters claimed theft of 3.1 TB of data
  • Stolen cache reportedly includes insurance company, credit rating files, AWS logs, configurations and PII; The NAIC says only financial reports and technical data were taken
  • Event seen June 11, revealed June 17; files leaked online suggest NAIC did not pay ransom as ShinyHunters continue to exploit zero-day across 100+ organizations

The National Association of Insurance Commissioners (NAIC) confirmed it suffered a cyber attack that resulted in the stolen data being leaked onto the dark web. While the company didn’t name the group responsible or mention the size of the stolen cache, the infamous ShinyHunters claimed responsibility, saying they snagged around 3.1 TB of information.

In a security notice published on the NAIC website, it was explained that the attackers managed to exploit a zero-day vulnerability in Oracle PeopleSoft. This is an Enterprise Resource Planning (ERP) software package designed to help businesses manage employees, finances, supply chains and more. Citing Google Mandiant, Cybernews says ShinyHunters first began exploiting the zero-day on May 27 and managed to compromise more than 100 organizations and 300 individuals before Oracle finally issued an emergency update on June 10.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top