On June 17, 2026, the National Association of Insurance Commissioners (NAIC) first disclosed to the public that there had been unauthorized access to its online infrastructure through its PeopleSoft systems. Over the past week, the NAIC has issued two more updates, each providing additional details and updating interested parties of the exact nature and extent of this cybersecurity breach. The NAIC maintains a data infrastructure that connects all 50 state insurance departments and thousands of licensed insurers on its host of filing and reporting platforms. The NAIC’s webpage dedicated to updating the public on this cyber event can be accessed here.
I. The Breach
According to the NAIC, on or about June 11, 2026, an unauthorized third party gained access to a portion of the NAIC’s systems by exploiting a “zero-day vulnerability” in Oracle PeopleSoft, a flaw unknown to the developer or its users at the time. The actor later posted to a leak site claiming to have taken roughly 3.1 terabytes of data across the NAIC’s core regulatory platforms, however, as of June 23, 2026, the NAIC asserts that it believes that claim to be an overstatement.
The NAIC states that the intruder, while inside PeopleSoft, a system used primarily for internal financial reporting by the NAIC, obtained credentials sufficient to reach certain data-storage areas, and that this access path has since been blocked and remediated.
II. June 17, 2026: The Disclosure
The NAIC reported on June 17, 2026, that it had identified, on or about June 11, unauthorized access to its PeopleSoft systems, and that it had activated its “incident response procedures” to contain and mitigate the impact of this breach. It stated that a thorough investigation was underway to determine what information might have been affected, and that it could not yet confirm the full scope of the incident.
The June 17, 2026, disclosure was accompanied by an “FAQ,” which answered questions such as, “what happened? [and] what has been impacted,” “what security measures does NAIC have in place to prevent this type of event,” and “when will the investigation be completed?” In response to those questions, and others, the NAIC reassured its commitment to handling the matter as a top priority and with the appropriate care and urgency.
III. June 18, 2026: Details on the Actor
On June 18, 2026, the NAIC provided a new update stating that it had learned the individual or group responsible had publicly claimed to have obtained NAIC data, and that it had no confirmation that any data from its systems had been published or released. Additionally, the NAIC stated that, based on public reporting, the incident appeared to be part of a wider campaign affecting many organizations that run the same software. The NAIC confirmed that its investigation with outside cybersecurity experts was still ongoing.
IV. June 23, 2026: The Current State of Disclosure
On June 23, 2026, the NAIC disclosed a significant amount of detailed information regarding the breach. In this update, the NAIC reiterated that the intruder entered its systems on June 11, 2026, through the PeopleSoft vulnerability, obtained the information needed for temporary access to certain data-storage areas, and that this path has since been blocked and reported. In addition to the earlier statement that outside cybersecurity experts were being employed, the most recent update informed that the FBI has also become involved.
The NAIC further reported that what the intruder reached, on its findings to date, fell into two categories: statutory financial reporting information, which was already publicly accessible before the incident through state websites, the InsData service, or resellers; and credit rating agency data covering rating determinations of insurer investments, excluding the agencies’ investment rationale reports. It stated that no personally identifiable information or payment data, including credit card or banking information, was reached. Additionally, the NAIC stated in its most recent update that that, although the responsible party claimed to have access to NAIC technology including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), the Uniform Certificate of Authority Application (UCAA), the Enterprise Data Platform (EDP), and Regulatory Data Collection (RDC), outside experts confirmed the intruder neither took that information nor compromised those reporting systems. The NAIC also emphasized that the systems operated by the state insurance departments themselves were not impacted. It listed additional systems and data it determined were not accessed, including “NIPR, Teammate, State Based Systems (SBS), employee personal data, electronic funds transfers, risk-based capital data, policyholder information, producer data, and event-registration payment information.”
Lastly, the NAIC addressed the current state of operations. As of June 23, 2026, day-to-day operations had returned to normal at the NAIC apart from two exceptions: it is meeting with credit rating providers to furnish third-party assurances so the designation process can resume, and online invoice payment through PeopleSoft remains unavailable. The NAIC stated in its most recent update that it anticipates giving rating agencies third-party verification of its systems and will take the steps necessary to restore services Lastly, the NAIC made clear that, if the responsible group releases data, it will engage experts to compare that data against its own. It stated that the process could take months, that it is prioritizing accuracy over speed, and that further updates will be communicated to stakeholders and posted on NAIC.org.
Troutman Pepper Locke will continue following this story and provide updates on any material developments.