Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NAIC Confirms Data Breach in Oracle PeopleSoft Hack

NAIC Confirms Data Breach in Oracle PeopleSoft Hack

Posted on June 29, 2026 By CWS

The National Association of Insurance Commissioners (NAIC) has disclosed its involvement in a recent cyberattack exploiting an Oracle PeopleSoft vulnerability. This breach is part of a wider hacking campaign that has raised significant concerns in the cybersecurity community.

Oracle PeopleSoft Vulnerability Exploited

The Oracle PeopleSoft zero-day vulnerability, identified as CVE-2026-35273, was revealed on June 11 when Oracle issued an urgent advisory. This vulnerability allows for remote code execution without authentication, posing a serious threat to affected systems. Although Oracle’s advisory did not highlight active exploitation, subsequent confirmations from Google and other entities have verified ongoing attacks.

The cybercrime group known as ShinyHunters has been linked to this campaign, claiming responsibility for targeting numerous organizations to extract sensitive data. The NAIC, a pivotal body in US state insurance regulation, has publicly acknowledged being one of the targets.

Details of the Security Incident

On June 26, the NAIC issued a security notice detailing the unauthorized access discovered on June 11. Hackers managed to penetrate their systems through the PeopleSoft vulnerability, accessing public statutory financial reporting information, credit rating agency data, and older technical logs and configurations.

Importantly, the NAIC reassured that no personally identifiable information or payment details were compromised. Furthermore, the systems of state insurance departments and various regulatory reporting structures remained unaffected, countering initial claims made by the hackers.

ShinyHunters’ Claims and Revisions

ShinyHunters included the NAIC in its list of victims on June 18, alleging the theft of over 105,000 files, equating to more than 3.1 terabytes of data, including 2.1 million insurer regulatory filing documents. However, a later clarification from the cybercriminals indicated that these figures were inflated due to an AI-generated data misinterpretation. The corrected statement reduced the theft to 260,000 documents and removed references to compromised systems as initially alleged by NAIC.

While the University of Nottingham is reportedly another victim of the same hack, it has not specifically associated its breach with the PeopleSoft vulnerability in its public disclosures.

Implications and Future Outlook

This incident highlights the persistent threat posed by sophisticated cyberattacks on major organizations. As more entities potentially affected by the Oracle PeopleSoft campaign come forward, the importance of robust cybersecurity measures and timely vulnerability patches is underscored. Both regulatory bodies and private organizations must remain vigilant against evolving cyber threats.

Security Week News Tags:cyber attack, Cybersecurity, data breach, data security, Hackers, insurance regulators, IT security, NAIC, Oracle PeopleSoft, ShinyHunters, unauthorized access, zero-day vulnerability

Post navigation

Previous Post: DCloud Uni-App Framework Fuels Global Crypto Scams
Next Post: Millenium RAT Malware Threat Grows, Infections Skyrocket

Related Posts

Cyber Insights 2026: External Attack Surface Management Cyber Insights 2026: External Attack Surface Management Security Week News
Minnesota Activates National Guard in Response to Cyberattack Minnesota Activates National Guard in Response to Cyberattack Security Week News
Zero Trust Is 15 Years Old — Why Full Adoption Is Worth the Struggle Zero Trust Is 15 Years Old — Why Full Adoption Is Worth the Struggle Security Week News
Phishing Exploits .arpa TLD in DNS Vulnerabilities Phishing Exploits .arpa TLD in DNS Vulnerabilities Security Week News
Gemini CLI Flaw Risked Severe Supply Chain Attack Gemini CLI Flaw Risked Severe Supply Chain Attack Security Week News
Cisco Unified CM Flaw Exploited by Hackers Cisco Unified CM Flaw Exploited by Hackers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark