The National Association of Insurance Commissioners confirmed a data breach involving an Oracle PeopleSoft zero-day vulnerability, with the hacking group ShinyHunters claiming to have stolen 3.1TB of sensitive information.
Key Points
- The NAIC identified the security breach on June 11 and publicly disclosed the incident on June 17.
- Attackers exploited a zero-day vulnerability in Oracle PeopleSoft software to gain unauthorized access to internal systems.
- ShinyHunters claims to have exfiltrated 3.1TB of data, including insurer regulatory filings, credit rating files, and AWS infrastructure logs.
- The NAIC maintains that the stolen data consists primarily of financial reports and technical files, denying that personal or banking information was compromised.
- Oracle released an emergency security update on June 10 to address the vulnerability, which affected over 100 organizations globally.