National Association of Insurance Commissioners
Disclosed Jun 29, 20262 months agoUnverified
NAIC says ShinyHunters took public data in PeopleSoft zero-day breach
The NAIC said ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 and stole mostly public financial filings, outdated logs and configuration files, denying any PII exposure. The group claimed 3.1 TB including credentials for regulatory systems.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jun 29, 2026 |
| Discovered | Jun 11, 2026 |
| Attack | Hacking |
| Data exposed | Internal documents, Credentials and tokens |
| Sector | Government · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Part of | Oracle peoplesoft (2026) |
Sources
| Source | |
|---|---|
| NAIC says public data stolen in ShinyHunters' PeopleSoft breachbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 29 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Sep 223 days ago | Extortion | Government | Unverified | Unknown | |
| Jun 103 months ago | Hacking | Education | Unverified | 455K |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.
Everything about National Association of Insurance Commissioners