KBRA Statement Regarding the National Association of Insurance Commissioners (NAIC) Cybersecurity Incident
KBRA is issuing this statement in the interest of transparency to our clients, investors, issuers, and other market participants regarding a cybersecurity incident recently disclosed by the National Association of Insurance Commissioners (NAIC).
The facts regarding the incident are set forth in the NAIC’s public Security Update, available on the NAIC’s website. The situation is evolving, and we encourage all clients to check for updates on the NAIC’s website for information on what data has been compromised.
The NAIC became aware of a cybersecurity breach affecting its systems on June 11, 2026. On June 18, the NAIC publicly disclosed the incident and subsequently notified KBRA. On June 26, the NAIC notified KBRA that unpublished KBRA ratings information submitted through our regulatory data feed had been exported during the incident. The NAIC requires KBRA and other credit rating agencies to provide these data feeds for NAIC designation purposes.
Based on the information provided to KBRA by the NAIC, the compromised data includes unpublished ratings information and related identifiers but did not include transaction or issuer names or information. On June 26, the NAIC informed KBRA that the compromised information involved in the incident had been uploaded to a site used to distribute data obtained through cyber incidents.







