Skip to content

National Association of Insurance Commissioners

Disclosed Jun 29, 20262 months agoUnverified

NAIC says ShinyHunters took public data in PeopleSoft zero-day breach

The NAIC said ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 and stole mostly public financial filings, outdated logs and configuration files, denying any PII exposure. The group claimed 3.1 TB including credentials for regulatory systems.

What is known

People affectedNot stated in the sources we have
DisclosedJun 29, 2026
DiscoveredJun 11, 2026
AttackHacking
Data exposedInternal documents, Credentials and tokens
SectorGovernment · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Part ofOracle peoplesoft (2026)

Sources

Source
NAIC says public data stolen in ShinyHunters' PeopleSoft breachbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalJun 29

Same campaign

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about National Association of Insurance Commissioners

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.