[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2f8mxh9euau4x":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":19,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":29,"dataClasses":30,"description":36,"seoTitle":8,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"1465d89728c52e77ce3b981d","NAIC2026","NAIC 2026 Security Incident","naic-2026-security-incident","naic.org","2026-06-11T00:00:00.000Z","2026-09-11T12:24:35.012Z","2026-09-11T14:24:12.907Z","2026-09-11T14:20:49.508Z","Official NAIC security update and independent reporting","https:\u002F\u002Fcontent.naic.org\u002Fabout\u002Fsecurity-update",[16,18],"https:\u002F\u002Fwww.securityweek.com\u002Finsurance-regulators-group-naic-hit-in-oracle-peoplesoft-hack\u002F",null,"unknown","people","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":28},"naic-2026-guvenlik-olayi","Unknown",[31,32,33,34,35],"Public statutory financial reporting information","Public and private credit rating determinations for investments","Security identifiers in credit rating feeds","Outdated logs","Configuration information","\u003Cp>The 2026 NAIC security incident came to light when the National Association of Insurance Commissioners \u003Cstrong>detected unauthorized access to part of its environment on June 11, 2026 through an Oracle PeopleSoft vulnerability that was unknown to the developer and users at the time\u003C\u002Fstrong>. NAIC said information obtained from PeopleSoft enabled temporary access to certain data-storage areas.\u003C\u002Fp>\u003Cp>The investigation found that the accessed or copied material included publicly available annual and quarterly statutory financial statements, public and private credit-rating determinations for investments, security identifiers in those feeds, and some outdated logs and configuration information. Some private ratings were confidential; rating-agency rationale reports and risk-based-capital data were not affected.\u003C\u002Fp>\u003Cp>NAIC promptly contained the access, blocked and remediated the path, engaged outside counsel and cybersecurity specialists, and began coordinating with the FBI. State insurance-department systems and the identified regulatory filing systems were not affected. After some rating providers paused feeds, certain NAIC Designation processes were suspended on June 18. Required feeds resumed by August 10, and publication resumed August 17.\u003C\u002Fp>\u003Cp>NAIC reported \u003Cstrong>no evidence that personally identifiable, banking, payment, policyholder, producer, or employee information was accessed or released\u003C\u002Fstrong>. An affected-person count therefore does not apply. The organization did not disclose when access began, how long it lasted, or further technical details; the entry uses the June 11 detection date.\u003C\u002Fp>","NAIC disclosed unauthorized PeopleSoft access and found no evidence that personal, banking, payment, policyholder, producer or employee data was accessed.","\u002Fuploads\u002Flogo\u002Fnaic-2026-guvenlik-olayi-1465d89728c5.webp",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":44,"websiteStatus":44,"websiteCheckedAt":19},"National Association of Insurance Commissioners","Insurance regulation","United States",""]