ShinyHunters claimed 264,000 regulatory filing PDFs from the June 2026 NAIC breach, spanning 2017 to 2024 across property, casualty, health and life. NAIC disputes that SERFF was the source, and outside experts confirmed core regulatory systems were not directly accessed. Not disputed: data was taken, published online, and portions authenticated by researchers. The exposure sits in infrastructure no individual carrier can secure.

Key Takeaways

  • 264,000 filing PDFs claimed across 2017 to 2024, with the credit-agency tranche alone reportedly around 45,000 files, out of 3.1 terabytes the group posted.
  • The vector was an Oracle PeopleSoft zero-day, exploited between May 27 and June 10 in a campaign Google Mandiant confirmed touched more than 100 organizations and 300 instances.
  • NAIC states outside experts confirmed no access to SERFF, NIPR, Teammate or State Based Systems, and no PII, payment, policyholder or risk-based capital data. It does not contest that taken data was published.
  • The seven-year window covers the most consequential P&C pricing period in two decades: post-pandemic frequency recovery, auto physical damage supply chain inflation, casualty social inflation, and the first full cyber underwriting cycle.
  • A carrier's lever on this infrastructure is submission discipline and confidentiality designation. It has no equivalent of the security investment it makes in its own environment.

What Is Disputed and What Is Not

Between May 27 and June 10, 2026, ShinyHunters exploited a zero-day in Oracle PeopleSoft in a campaign Google Mandiant later confirmed had reached more than 100 organizations and 300 instances before an emergency patch closed it. NAIC identified unauthorized access to its PeopleSoft environment on June 11. The group posted on June 18, claiming 3.1 terabytes from systems including SERFF, OPTINS, UCAA, EDP and RDC plus credit-feed data from Moody's, Fitch, S&P, Kroll, DBRS and AM Best, with the credit-agency tranche alone at roughly 45,000 files.

NAIC pushed back with specificity: outside cybersecurity experts confirmed no access to SERFF, NIPR, Teammate or State Based Systems, and no personally identifiable information, payment data, policyholder information or risk-based capital data. "The incident was promptly contained," it said. What it did not contest is that data taken in the breach has been published online, and researchers reviewing the published set confirmed portions as authentic NAIC material (Insurance Journal).

The vector is the structural detail. PeopleSoft is an enterprise resource planning suite handling HR, finance and administration; at NAIC it runs internal operations rather than filing workflows. A zero-day there provides an enterprise foothold, and what that foothold reaches depends on how the instance connects to adjacent systems. That a group could credibly claim filing-adjacent data without the filing systems being the entry point is how lateral movement works: networked systems do not stay partitioned once an attacker has time inside the perimeter.

The Sensitive Part of a Filing Is Not the Rate

The most sensitive actuarial material in a rate filing is rarely the indicated change. A prior-approval package stratifies across at least three layers. The public exhibit holds proposed rates, classification schedule and effective date. The actuarial memorandum, which carriers can flag confidential for trade-secret protection, holds the indication: selected loss development factors, trend selections, credibility weights, territorial relativities and the data source behind each. Behind that sit loss triangles, competitor benchmark analysis and catastrophe model selection and output.

SERFF tracks the full objection-and-response workflow, which means it holds the regulator's challenge and the carrier's precise technical defense. In contested lines the objection often reveals the ceiling a state will accept, and the response shows the argument that moved it. Across filing cycles and carriers in one state, those documents disclose both the individual pricing rationale and the regulatory temperature for rate adequacy. Neither is recoverable from any public source.

The 2017-to-2024 window is where that becomes valuable rather than merely sensitive. In personal auto, the archive would show the specific trend factors each carrier selected coming out of the post-pandemic frequency recovery, how each responded to supply chain inflation in physical damage between 2021 and 2023, and how quickly each recognised severity acceleration and filed for it. Carriers that moved early show different filing timelines from carriers that held and revised later, and that sequencing across 50 states describes pricing judgment and response latency that the approved rates alone never show.

In homeowners the value concentrates in catastrophe model selection. Carriers using different vendor models make different pricing decisions in the same coastal or wildfire territory because the models diverge at the tail, and a filing carrying selected average annual loss by peril plus the model behind it discloses which model the carrier trusts. Aggregated across carriers in one state, those filings show where model divergence is widest, which is where both the pricing opportunity and the mispricing risk sit. In first-generation cyber, filed on thin carrier-specific data, the memos disclose what assumptions were used before industry data existed and how they moved as losses developed.

The One Exposure a Carrier Cannot Buy Down

Carriers now run cybersecurity as a board-level discipline. The NAIC Insurance Data Security Model Law, adopted in some form in more than two dozen states, requires written information security programs, annual risk assessments and documented third-party vendor oversight. Endpoint detection, network segmentation and privileged access management reduce breach probability and limit blast radius inside the carrier's own environment.

Exposure Type Who Controls Security Carrier Lever Breach Blast Radius
Carrier’s own IT systems The carrier Direct: security investment, architecture, access controls One carrier’s data
Third-party vendor systems (e.g., Verisk, Guidewire) The vendor Indirect: contract security requirements, SOC 2 review, right-to-audit Data shared with that vendor by all clients
Regulatory filing infrastructure (SERFF, NAIC) NAIC / state departments Minimal: submission discipline, confidentiality designation, advocacy Multi-carrier filing data across all 50 states and multiple years

The filing infrastructure sits outside that perimeter. SERFF is contributed to, not owned, and a carrier that invests heavily in its own security has no equivalent lever over the shared platform holding its filings alongside every competitor's. The Model Law's vendor obligations run one direction: carriers must evaluate vendors who access carrier data, and carriers are not positioned to evaluate the security posture of systems they are legally required to submit to.

That is the accumulation structure the BIS and IAIS described in FSI Insights No. 75 in June 2026, noting that high concentration in the use of certain software, operating systems, hardware and cloud providers exacerbates the potential for accumulation risk. Their illustrative event is the July 2024 CrowdStrike outage, one faulty update disrupting millions of Windows systems across airlines, banks and exchanges at once. Regulatory filing infrastructure has the identical feature: one platform, one administration, the filing data of hundreds of carriers.

NAMIC had named the adjacent version before this happened. Commenting on a proposed centralised cyber incident reporting repository, it warned that aggregating descriptions of carrier cyber events in a single NAIC system would create "a treasure trove for cyber criminals" by mapping which vulnerabilities each carrier had closed and which remained open.

Retention is what sets the depth. A seven-year archive exists because filing data is held long after the rates it supports are superseded, and a 2018 methodology for a product line since revised carries limited regulatory value against measurable ongoing competitive sensitivity. That is the one dimension of the exposure the carriers themselves put there.

Further Reading

Sources

  1. Insurance Journal, “NAIC Says Data Taken in Hack Has Been Published Online” (June 25, 2026) — NAIC confirmation that published data is authentic and review of ShinyHunters’ post-breach assertions.
  2. Insurance Journal, “NAIC Victim of Cyber Incident Via PeopleSoft System” (June 24, 2026) — Initial breach reporting, PeopleSoft zero-day vector, NAIC response, and Google Mandiant campaign attribution.
  3. NAIC, Security Incident Update (June 2026) — NAIC official statement on confirmed access, systems not compromised, and outside cybersecurity expert findings.
  4. CyberNews, “ShinyHunters Posts 3.1TB from NAIC Breach, Claims Data Linked to Key Insurance Systems” (June 2026) — ShinyHunters’ claimed data volume, system list, and the approximately 45,000 credit-agency files in the published dataset.
  5. BIS/FSI and IAIS, FSI Insights on Policy Implementation No. 75: Cyber Insurance Unpacked (June 2026) — Accumulation risk framework, cloud concentration as systemic exposure, and the CrowdStrike July 2024 outage as the reference event for shared-infrastructure systemic risk in financial services.
  6. NAIC, Cybersecurity (H) Working Group (2026) — Mandate, scope, and cross-state regulatory response coordination for insurance industry cyber events.
  7. SERFF (System for Electronic Rate and Form Filing), NAIC (2026) — Platform overview, filing access architecture, and confidentiality designation framework for rate and form filings.
  8. The Insurer, “Threat Actor Group ShinyHunters Claims to Have Obtained NAIC Data” (June 22, 2026) — Initial ShinyHunters claim, dark-web post details, and the regulatory data categories allegedly included.
Feedback

We are seeking feedback on how to improve the site and deliver high-quality content relevant to actuaries. Help us make it better.

Submit feedback

Stay ahead with daily actuarial intelligence - news, analysis, and career insights delivered free.

Subscribe to Actuary Brew Browse All Insights