NAIC confirmed a data breach after stolen data was posted online by ShinyHunters. Here’s what happened, what was shared, and why insurance-related data can still matter to you right now.
Table of Contents
What Happened?
NAIC is the organization that helps regulate the U.S. insurance industry, and the attack was linked to the vulnerability in Oracle PeopleSoft software. Oracle PeopleSoft is software that many organizations use to manage finance, payroll, and other business operations.
NAIC said it discovered the security incident on June 11, 2026, and publicly disclosed it on June 17. On June 26, the hacker group ShinyHunters published what it said was 3.1 terabytes of stolen data connected to NAIC systems.
The attack was linked to a zero-day vulnerability in Oracle PeopleSoft. A zero-day vulnerability is a software flaw that criminals discover before the software company has released a fix.
NAIC said its main insurance platforms continued operating normally and that investigators found no evidence its core regulatory systems were broken into.
What Information Was Taken?
NAIC said it found no evidence that hackers accessed personally identifiable information (PII), payment card details, bank account information, employee personal records, or policyholder data. State insurance department systems were also not affected.
However, the files published by ShinyHunters appear to include:
- More than 264,000 insurance regulatory filing documents
- Around 2,000 customer and order records containing names, email addresses, and payment transaction identifiers
- Financial reports submitted by insurance companies
- Cloud configuration files and system backups (files that show how computer systems are set up and copies of important data)
- SQL scripts (database instructions) and stored credentials (saved usernames, passwords, or security keys) that may help attackers understand internal systems
- Files linked to NAIC’s production cloud infrastructure (the live cloud systems the organization uses every day)
While many insurance filings are already public, technical files such as cloud settings, backups, and system credentials could be much more valuable to cybercriminals because they may reveal how important systems are built and connected.
That’s why data breaches can continue causing problems long after they disappear from the headlines.
Criminals often combine information from different data breaches or data leaks to create convincing phishing emails, impersonation scams, and identity theft attempts.
Many people also do not realize their information was leaked in earlier incidents until suspicious activity appears months or even years later.
If you are not sure whether your information was leaked somewhere online, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
How Hackers Broke Into Oracle PeopleSoft Systems
NAIC said the attack was linked to a recently discovered Oracle PeopleSoft software vulnerability.
A software vulnerability is a weakness that allows criminals to enter systems without permission.
According to Google Mandiant — Google Cloud’s cybersecurity research team — attackers exploited this security flaw between late May and early June before Oracle released an emergency security update. During that time, more than 100 organizations were reportedly affected.
Investigators said they found no evidence that NAIC’s core insurance platforms or state insurance department systems were accessed.
Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.
Check my safetyWhat the NAIC Breach Shows About Critical Systems
The NAIC incident shows that cybercriminals increasingly target organizations that support important services rather than individual consumers.
Even if NAIC did not store your information directly, organizations in finance, healthcare, insurance, and government remain attractive targets because they hold valuable data.
That means a single cyberattack can affect an entire industry.
According to IBM’s X-Force Threat Intelligence Index 2025, 70% of the attacks IBM responded to targeted critical infrastructure organizations. IBM is a global technology company, and its X-Force team studies cyberattacks and helps organizations respond to them.
NAIC supports systems used across the U.S. insurance industry, which is part of the nation’s critical financial sector.

5 Simple Ways to Better Protect Your Information
You cannot control every company that stores your information, but these simple habits can help reduce your risk:
1. Watch for insurance-related phishing messages
Criminals may use news about this breach to send fake emails or text messages that appear to come from insurance companies or regulators.
If a message asks you to click a link, update your account, or share personal information, visit the company’s official website yourself instead of using the provided link.
2. Protect your email account
Your email account connects to many of your online accounts. If someone gains access to it, they may be able to reset passwords elsewhere.
To better secure your email account, create a strong password and turn on two-step verification, which requires a second security code when you sign in. On most email services, you should open Settings > Security to enable it.
If you are not sure how to set up extra protection, the Futureproof Email Protection tool guides you through the process step by step.
Email Protection helps you create strong passwords and set up two-step verification to secure your email account.
3. Check your financial accounts regularly
Small unauthorized charges can appear before larger fraud attempts.
Review your bank and credit card activity every few days. If you notice a transaction you do not recognize, contact your bank immediately.
4. Keep your devices updated
Software updates often fix security weaknesses before criminals can abuse them.
Turn on automatic updates by opening your device’s Settings and selecting Update or Software Update. This helps install security fixes as soon as they become available.
5. Be careful with requests for personal information
After major breaches, criminals often pretend to represent trusted organizations.
If someone unexpectedly asks for your Social Security number, insurance information, or payment details, contact the organization directly using its official phone number or website before responding.
Your Data Can Be Affected by Companies You Never Contact
The NAIC breach shows that your personal information may pass through many organizations you never interact with directly.
That makes it important to stay alert after major cybersecurity incidents, watch for unexpected messages, and regularly check whether your information has appeared in data leaks.
Tools such as Futureproof can help you discover problems earlier, strengthen your accounts, and give you practical steps to stay safer online.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
