The National Association of Insurance Commissioners (NAIC) has suspended some of its operations, including investment risk designations for insurers, following a cyberattack detected on June 11. This incident stemmed from a broad campaign targeting a zero-day vulnerability in Oracle's PeopleSoft software, which the NAIC primarily uses for internal financial reporting. While the hackers, identified as ShinyHunters ransomware group, claimed to have stolen 3.1 terabytes of data, the NAIC's internal investigation and external cybersecurity experts assert that the scope of data obtained is significantly less than claimed.
NAIC has confirmed that publicly available statutory financial reporting information and credit rating agency data, including rating determinations of insurer investments, were accessed. However, the organization stressed that no personally identifiable information (PII), payment information, credit card details, banking information, employee data, electronic funds transfer data, risk-based capital data, policyholder information, producer data, or event registration payment information was compromised. Key regulatory reporting systems like SERFF, OPTins, UCAA, EDP, and RDC were also not affected.
In response to the breach, the NAIC engaged outside counsel and cybersecurity experts, coordinated with the FBI, and contacted its cyber insurance carrier. They swiftly contained the incident and remediated affected systems. Credit rating providers temporarily paused their data feeds and investment designation services while the NAIC provides independent security assurances. The NAIC has faced criticism for its communication handling, with groups like the National Association of Mutual Insurance Companies (NAMIC) and the American Property Casualty Insurance Association (APCIA) expressing concerns about the timeliness and clarity of alerts to member companies. The investigation and review of potential data releases are expected to continue for several months.