NAIC communications
Keep notices, emails, updates, technical bulletins, and correspondence with NAIC concerning the incident or affected systems.
Hall Attorneys is reviewing the June 2026 NAIC PeopleSoft incident while emphasizing NAIC's current finding that policyholder and employee personal data were not accessed.
NAIC says policyholder information was not accessed
date reported by NAIC
NAIC says temporary access was blocked
Answer at a glance
NAIC says it identified unauthorized access to part of its environment on June 11, 2026, through an Oracle PeopleSoft zero-day. The unauthorized party used information obtained in PeopleSoft to gain temporary access to certain data-storage areas.
NAIC says it contained the incident, blocked and remediated the temporary access, engaged outside counsel and cybersecurity experts, and coordinated with the FBI. The group responsible published data on June 25.
NAIC's current findings do not support describing this as a policyholder or employee-personal-data breach. Its July FAQs say the insurer data in scope was public statutory reporting data, while certain private credit-rating determinations were also accessed.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
Mandiant observed activity aligned with CVE-2026-35273 before Oracle's security alert.
NAIC says it identified access to a portion of its environment, contained the incident, and began work with outside experts and the FBI.
NAIC acknowledged publication, then described the accessed data and listed systems and personal-data categories that its investigation found were not accessed.
NAIC clarified the public financial-reporting scope, private and public rating determinations, unaffected systems, and the temporary pause affecting some NAIC Designations.
Reported data categories
NAIC's current findings center on regulatory and rating information, not a cohort of individual insurance consumers. The categories below reflect NAIC's July incident FAQs.
Important distinction
NAIC says no policyholder information or employee personal data was accessed. Unless those findings change, an individual consumer affected-person count would be unsupported.
Who may want to contact us
The current official record does not establish an affected consumer cohort. Questions are more likely to concern insurers, credit-rating providers, and organizations whose data may fall within the described repositories.
Credit-rating providers concerned about private rating determinations or security identifiers
Insurers seeking to determine whether company-specific information falls outside NAIC's described public-data scope
Organizations receiving a direct NAIC incident communication identifying their data
People or organizations receiving suspicious NAIC-themed communications that may use incident details
What to preserve
Preserve relevant records, but do not send confidential rating materials, complete financial records, credentials, or regulated non-public information through ordinary website forms.
Keep notices, emails, updates, technical bulletins, and correspondence with NAIC concerning the incident or affected systems.
Preserve records showing what information your organization submitted, transmitted, licensed, or made available to NAIC and when.
Keep agreements, system documentation, policies, and markings showing whether particular rating or regulatory data was public, private, restricted, or confidential.
Preserve phishing, impersonation, credential requests, or other messages that reference NAIC, ratings, filings, or incident-specific information.
Document delayed feeds, designation issues, remediation work, system changes, or other operational effects tied to the incident.
Track incident-response time, professional fees, remediation expense, and other concrete costs or losses.
Investigation focus
Hall Attorneys is reviewing whether later evidence changes NAIC's stated scope, how private rating determinations were handled, and whether organizations experienced concrete misuse or loss.
Public records reviewed
NAIC's continuously updated incident page is the controlling source for current scope. Technical sources explain the underlying PeopleSoft vulnerability and campaign.
National Association of Insurance Commissioners ·
NAIC's incident timeline, findings on accessed data, list of information not accessed, remediation summary, and detailed FAQs.
Read source: Security Incident UpdateOracle ·
Oracle says the PeopleSoft PeopleTools vulnerability is remotely exploitable without authentication, may allow remote code execution, and affects supported versions 8.61 and 8.62.
Read source: Security Alert Advisory — CVE-2026-35273Google Threat Intelligence Group and Mandiant ·
Describes activity attributed to UNC6240, also known as ShinyHunters, observed from May 27 through June 9 and aligned with exploitation of CVE-2026-35273.
Read source: ShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitBleepingComputer ·
Independent reporting on NAIC's response, the published data, and disputed claims about the incident's scale.
Read source: NAIC says public data stolen in ShinyHunters' PeopleSoft breachContact the firm
Contact Hall Attorneys with the type of NAIC relationship, the general category of data at issue, and any incident communication or concrete loss. Do not include credentials, confidential rating materials, or complete regulated filings in an initial message.
Frequently asked questions
NAIC's current findings say policyholder information was not accessed. The page will need revision if NAIC later changes that finding.
NAIC says employee personal data was not accessed.
NAIC lists public statutory financial reporting information, public and private credit-rating determinations, security identifiers, and routine outdated logs or configuration information.
No consumer cohort has been established. NAIC says policyholder information was not accessed, so presenting a consumer affected-person count would not be supported by its current findings.
Yes. NAIC acknowledged on June 25 that data taken from its environment was published and then issued additional findings about the scope.
Attorney Advertising
Hall Attorneys is not affiliated with National Association of Insurance Commissioners or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.