The National Association of Insurance Commissioners (NAIC) has confirmed it was targeted in the recent hacking campaign that exploited an Oracle PeopleSoft zero-day vulnerability.

The PeopleSoft zero-day attacks came to light on June 11, when Oracle published an out-of-band advisory for a vulnerability tracked as CVE-2026-35273, which allows unauthenticated remote code execution.

The company did not mention in-the-wild exploitation in its public advisory, but Google and others confirmed seeing attacks.

The ShinyHunters cybercrime group appears to be behind the campaign, claiming to have targeted many organizations to steal their data.

The US state insurance regulatory body NAIC has come forward to say that it was targeted in the campaign.