Summary

The National Association of Insurance Commissioners (NAIC) has confirmed a significant cyberattack on its Oracle PeopleSoft systems, exposing portions of its data infrastructure. The breach, attributed to the prolific ShinyHunters group, exploited CVE-2026-35273 — a critical unauthenticated remote code execution vulnerability in PeopleSoft Enterprise PeopleTools.

The attack window ran from May 27 to June 9, 2026, but was only publicly disclosed on June 23. NAIC is not alone: the same vulnerability has impacted over 100 organizations globally, with a significant concentration in the higher education sector. ShinyHunters has been tied to more than half of confirmed “mega-breaches” through the first half of 2026.

The CVE-2026-35273 vulnerability enables unauthenticated attackers to achieve full remote code execution on PeopleSoft instances, making any internet-exposed deployment a target. Organizations running PeopleSoft are urged to verify their patch status immediately and conduct forensic reviews of the May-June window.

Source

Commentary

ShinyHunters continues to be the most prolific breach group of 2026, and this campaign illustrates why: they find one critical RCE, automate exploitation, and sweep through entire sectors. Oracle PeopleSoft is deeply embedded in insurance, government, and higher education — institutions that are often slow to patch and rich in sensitive personal data.

The 100+ victim count from a single CVE is a reminder that mass exploitation campaigns aren’t slowing down. If you run PeopleSoft in any capacity, assume you were targeted during the May-June window and validate your exposure. The breach disclosure lag — identified June 11, announced June 23 — also highlights the ongoing gap between detection and transparency.

By Allan