AUTO-UPDATED

NAIC confirms data breach with ShinyHunters claiming 3.1TB of data stolen in Oracle zero-day attack

The National Association of Insurance Commissioners confirmed a data breach involving an Oracle PeopleSoft zero-day vulnerability, with the hacking group ShinyHunters claiming to have stolen 3.1TB of sensitive information.

Key Points

  • The NAIC identified the security breach on June 11 and publicly disclosed the incident on June 17.
  • Attackers exploited a zero-day vulnerability in Oracle PeopleSoft software to gain unauthorized access to internal systems.
  • ShinyHunters claims to have exfiltrated 3.1TB of data, including insurer regulatory filings, credit rating files, and AWS infrastructure logs.
  • The NAIC maintains that the stolen data consists primarily of financial reports and technical files, denying that personal or banking information was compromised.
  • Oracle released an emergency security update on June 10 to address the vulnerability, which affected over 100 organizations globally.

Why it Matters

This incident highlights the significant risks posed by zero-day vulnerabilities in widely used enterprise resource planning software. The breach underscores the importance of rapid patch management for organizations handling sensitive regulatory and financial data to prevent large-scale exfiltration by threat actors.
TechRadar Published by Sead Fadilpašić
Read original