In 2026, the National Association of Insurance Commissioners (NAIC) experienced a cybersecurity incident involving unauthorized access to its PeopleSoft systems. As of June 26, 2026, NAIC has not confirmed what specific information was accessed or if any data was publicly released. The incident was carried out by the cybercrime group ShinyHunters.
The scope of potential data exposure is still under review, and no specific number of affected individuals has been confirmed. Data types potentially at risk include personal and organizational records such as names, Social Security Numbers, and other personnel data. NAIC has not yet issued breach notification letters, as the investigation is ongoing. No official breach notification letters, DOJ actions, or state AG lawsuits have been filed against NAIC yet.
Details can emerge later as investigations continue, and official notices may be delayed.