GoFirm
Back to Blog
Case Studies·3 min read

ShinyHunters got inside the US insurance regulator. Then nothing stopped them.

By GoFirm

On 29 June 2026, ShinyHunters published 3.1 terabytes of data claimed from the National Association of Insurance Commissioners, the body that co-ordinates insurance regulation across all 50 US states and holds filings from thousands of licensed carriers. Attribution was confirmed by Google's Mandiant. The FBI is investigating.

The attack started in late May, when ShinyHunters exploited a critical flaw in Oracle's PeopleSoft software rated 9.8 out of 10 for severity, a vulnerability that required nothing more than a network connection to execute. Oracle released no advisory for 14 days. In that window, the same flaw was used to compromise more than 100 organisations worldwide. The NAIC was one of them.

What the breach produced was not just exfiltrated data. It produced stored credentials tied to live production systems, cloud infrastructure logs and configuration files, statutory financial statements submitted by thousands of insurers, and credit rating data containing the CUSIP and ISIN identifiers used in global debt markets. Security researchers have noted that infrastructure files of this kind give a capable attacker a map of internal architecture enabling follow-on operations months after the original breach. The NAIC has temporarily halted assigning investment designations to insurer portfolios. Credit rating agencies have suspended their data feeds. This is not a recovered incident. It is a live one.

The instinct after a breach like this is to focus on the vulnerability: Oracle's 14-day silence, the unpatched window, the perimeter that failed. Those are real failures worth addressing. They are not the whole story.

An intrusion is the beginning of a sequence, not the end of one. ShinyHunters got inside through a software flaw. That happens. What converted an intrusion into a catastrophic, irreversible data exposure was everything the attacker did next: moving laterally through internal systems, harvesting credentials, extracting regulatory filings, pulling configuration files. Each of those was a distinct, high-consequence action. Each one executed without a single check beyond the credential already in the attacker's hand.

This is the gap that perimeter thinking cannot close, and that detection-and-response frameworks reach too late to close. The credential ShinyHunters obtained was real. It came from a legitimate system. Any identity-layer check it passed would have passed correctly, because the credential was genuine. Behavioral monitoring looking for anomalous patterns would have needed time to establish a baseline before it could recognise drift. By then, the data was gone.

The question that was never asked before any of those actions completed was the only one that would have mattered: is the named authority behind this action actually the one initiating it, confirmed right now, on a device they control, out of band from the system being accessed? That question does not care whether the presenting credential is real. It does not care whether the behavior looks anomalous. It asks whether a living, identified person with standing authority over this specific action has confirmed it. If not, the action does not execute.

The data-theft methodology ShinyHunters used reflects a broader shift. Data-theft-only attacks, steal and publish without deploying ransomware, rose from 49% of extortion cases in the first half of 2025 to 65% in the second half. The leverage is exposure, and once data is published on a dark web leak site, no recovery operation reverses it. The harm is not access being denied. The harm is the actions that executed while access was held.

An unpatched vulnerability is a door left open. An execution boundary without confirmation is a vault left unlocked. The door matters. The vault is where the loss actually happens.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

Sellers, M. 2026. Terabytes of data dumped on the dark web after US insurance regulator hacked. Insurance Business, 29 June 2026. https://www.insurancebusinessmag.com/asia/news/cyber/terabytes-of-data-dumped-on-the-dark-web-after-us-insurance-regulator-hacked-580540.aspx

Share this article