NAIC Says ShinyHunters Walked Out With Public Data and Stale Logs After PeopleSoft Zero-Day Hit
The regulator-of-regulators confirms an Oracle PeopleSoft zero-day was the entry point, but disputes the extortion crew's claims about what was taken.

Key points
- NAIC says the ShinyHunters intrusion yielded publicly available records, outdated logs, and configuration files.
- The entry point was a zero-day in an internet-facing Oracle PeopleSoft server; no CVE has been attached publicly.
- NAIC says no production policyholder data and no supervisory examination files were accessed.
- ShinyHunters is better understood as a brand than a fixed crew; operator tradecraft varies between intrusions.
- Defenders running PeopleSoft on-prem or in IaaS should audit egress logs and confirm Oracle's latest CPU landed on the WebLogic tier.
What did ShinyHunters actually take?
NAIC says the actor reached systems holding logs, configuration artifacts, and material already public through its regulatory portals. Production policyholder data was not among it. Neither were supervisory examination files. That is NAIC's characterisation, and the group has not publicly accepted it.
NAIC is the coordinating body for U.S. State insurance regulators. A compromise there sits upstream of a great deal of sensitive financial supervisory data, which is exactly what ShinyHunters appears to be trading on with its leak-site posturing.
How did they get in?
The intrusion vector was a zero-day in an internet-facing Oracle PeopleSoft server. NAIC has not publicly attached a CVE to the bug. This is the same platform ShinyHunters, tracked by Mandiant as UNC6240, used against university networks in June, as we reported on 11 June. CVE-2026-35273, a CVSS 9.8 remote code execution flaw, received an Oracle patch that month, though Oracle stayed quiet on its zero-day status. Without vendor confirmation that a distinct bug underlies the NAIC incident, treat "zero-day" as the victim's characterisation for now.
Should you trust the ShinyHunters label?
Some researchers treat ShinyHunters as a brand more than a fixed set of operators. Infrastructure overlaps between intrusions, but operator tradecraft does not always follow. The cluster has shifted from straight data theft toward named-and-shamed extortion against enterprise ERP tenants. The TTPs are consistent: find an internet-exposed enterprise application, harvest data, post a sample, demand payment. Whether the same people ran each campaign flying this flag is a different question. The name has been claimed in cases where the underlying access broker was almost certainly someone else.
Should you worry?
If you run PeopleSoft on-prem or in IaaS, the practical position is unchanged. Inventory every internet-facing PeopleSoft instance. Audit the Integration Broker and any custom servlets. Pull egress logs for the window NAIC has not yet narrowed publicly. Confirm Oracle's latest Critical Patch Update actually landed on the WebLogic layer underneath.
NAIC says it has notified law enforcement and brought in outside incident response. It has not confirmed whether it received an extortion demand or how it intends to respond. If the answer is no, expect the leak cadence to accelerate.



