:

NAIC BREACH: SHINYUNTERS STEALS PUBLIC DATA VIA PEOPLESOFT ZERO-DAY

AI DESK1 MIN READ
MON, JUN 29, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The National Association of Insurance Commissioners confirmed that the ShinyHunters extortion group breached its systems through a zero-day vulnerability in Oracle PeopleSoft. The attackers accessed only publicly available data, outdated logs, and configuration files.

NAIC disclosed the incident after ShinyHunters exploited an unpatched vulnerability in its PeopleSoft server. The group, known for extortion-based attacks, has claimed responsibility for the breach. According to NAIC's assessment, the stolen data consists primarily of information already in the public domain, historical system logs, and server configuration details. No current sensitive records or personal information appears to have been compromised. ShinyHunters has previously targeted major corporations and organizations, typically demanding ransom payments and threatening to publish stolen data. The group's breach of NAIC—a regulatory body representing state insurance commissioners—marks another high-profile target. Oracle has not yet released a patch for the exploited zero-day vulnerability. NAIC has notified relevant authorities and is implementing additional security measures to prevent further unauthorized access.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.

1H AGOAI Desk

Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.

1H AGOIndustry Desk

A new survey reveals strong public opposition in the UK to government surveillance of encrypted communications. The findings highlight growing concern over privacy rights as lawmakers continue debating message scanning proposals.

1H AGOIndustry Desk

PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.