Executive Summary
In June 2026, the National Association of Insurance Commissioners (NAIC) experienced a cyberattack by the ShinyHunters group, who exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft servers. The attackers claimed to have stolen 3.1 TB of data, including insurer regulatory filings and AWS infrastructure configurations. NAIC's investigation indicated that only publicly available data, outdated logs, and configuration files were accessed, with no evidence of personal or financial data exposure. The breach led to operational disruptions, such as temporary suspension of data feeds by credit rating agencies and a pause in NAIC's investment designation work.
This incident underscores the critical importance of promptly addressing zero-day vulnerabilities and implementing robust security measures to protect sensitive data. Organizations must remain vigilant against sophisticated threat actors like ShinyHunters, who continue to exploit unpatched systems, emphasizing the need for proactive cybersecurity strategies and timely software updates.
Why This Matters Now
The exploitation of zero-day vulnerabilities by groups like ShinyHunters highlights the urgent need for organizations to prioritize timely patching and comprehensive security protocols to safeguard against data breaches and operational disruptions.
Attack Path Analysis
The ShinyHunters group exploited a zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273) to gain unauthorized access to NAIC's systems. They escalated privileges within the PeopleSoft environment, enabling further access. The attackers moved laterally to internal data storage locations, accessing sensitive information. They established command and control channels to maintain persistent access. Data, including publicly available reports and configuration files, was exfiltrated. The breach led to operational disruptions and reputational damage for NAIC.
Kill Chain Progression
Initial Compromise
Description
Exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access.
Related CVEs
CVE-2026-35273
CVSS 9.8An easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers with network access via HTTP to compromise the system, potentially resulting in a complete takeover.
Affected Products:
Oracle PeopleSoft Enterprise PeopleTools – 8.61, 8.62
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
OS Credential Dumping
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Insurance
Direct impact from NAIC breach exposing insurer regulatory filings, financial reports, and stored credentials for critical insurance regulatory platforms like SERFF.
Higher Education/Acadamia
High vulnerability to ShinyHunters' PeopleSoft zero-day attacks, with education sector being primary target for data theft and extortion campaigns.
Financial Services
Critical exposure through Oracle PeopleSoft systems handling sensitive financial data, requiring enhanced egress security and encrypted traffic controls for compliance.
Government Administration
Regulatory oversight systems compromised affecting state-based insurance platforms, requiring zero trust segmentation and threat detection capabilities for government data protection.
Sources
- NAIC says public data stolen in ShinyHunters' PeopleSoft breachhttps://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/Verified
- Oracle Warns PeopleSoft Customers After Critical Zero-Day Exploitedhttps://www.techrepublic.com/article/news-oracle-peoplesoft-zero-day-shinyhunters/Verified
- Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHuntershttps://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF would likely have constrained the ShinyHunters' ability to escalate privileges, move laterally, and exfiltrate data within NAIC's cloud environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit the vulnerability could be limited by reducing the exposure of vulnerable services.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be constrained by limiting access to sensitive resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement could be restricted, reducing the risk of accessing sensitive data.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could be limited, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data could be constrained, reducing the risk of data loss.
The overall impact of the breach could be reduced, limiting operational disruptions and reputational damage.
Impact at a Glance
Affected Business Functions
- Regulatory Reporting
- Data Management
- IT Infrastructure
Estimated downtime: 14 days
Estimated loss: N/A
Publicly available statutory financial reports, credit rating agency data, outdated logs, and configuration information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Utilize Multicloud Visibility & Control to monitor and manage security across all cloud environments.
- • Apply Egress Security & Policy Enforcement to control and monitor data exfiltration attempts.



