Key Takeaways
- ShinyHunters claimed to have breached SERFF — the system that contains every homeowners rate filing in the country. NAIC’s cybersecurity review found SERFF was not accessed. The distinction matters enormously for carriers mid-filing.
- NAIC discovered the breach on June 11 but didn’t post its first public update until June 17 — a six-day gap that NAMIC and APCIA called out in formal letters to NAIC President Scott White. The same communication standards NAIC imposes on insurers after a breach were not followed here.
- What was actually taken is narrower than ShinyHunters claimed: publicly available statutory financial reporting data and credit rating agency rating determinations. No PII, no payment data, no policyholder data. But the review is still ongoing, and NAIC says the full scope could take weeks to confirm.
- If you’re a homeowner, nothing in your dec page was exposed. This breach lives in the regulatory and financial reporting infrastructure — not in consumer policy systems. The real exposure is to carriers and rating agencies whose confidential investment-grade data may have been in those credit files.
What Happened and When
On June 11, 2026, the National Association of Insurance Commissioners detected unauthorized access to its IT systems through a zero-day vulnerability in Oracle PeopleSoft, tracked as CVE-2026-35273, a critical unauthenticated remote code execution flaw with a CVSS severity score of 9.8 out of 10. Oracle published no advisory until June 10, which means the flaw was being actively exploited for at least two weeks before any patch existed. The NAIC uses PeopleSoft primarily for internal financial reporting.
The NAIC posted its first public update on June 17. On June 25, the ShinyHunters ransomware group published the stolen data online. That same day, the NAIC confirmed it: the data taken from its environment had been published by the group responsible. By June 25, NAIC’s preliminary review with an outside cybersecurity consultant had identified what was actually in the posted dataset, publicly available statutory financial reporting information and credit rating agency data, specifically rating determinations of insurer investments. No personally identifiable information, no payment data, no policyholder records, no employee data, no electronic funds transfer data.
ShinyHunters claimed the haul was larger, 3.1 terabytes, allegedly spanning the System for Electronic Rate and Form Filing (SERFF), the Online Premium Tax for Insurance (OPTins), the Uniform Certificate Authority Application (UCAA), the Enterprise Data Platform (EDP), and the Regulatory Data Collection (RDC) system. Outside cybersecurity experts engaged by the NAIC found that those regulatory systems were not accessed. State insurance department systems were also unaffected, NAIC said.
Why SERFF Matters for Home Insurance Rate Filings
The SERFF claim is the one that home insurance policyholders and carriers should understand most clearly. SERFF is the filing system that every state insurance department uses to receive, track, and approve rate filings. When State Farm files for a 17% emergency rate increase in California, it goes through SERFF. When Allstate files a 22.7% increase in Texas, it goes through SERFF. When a carrier’s SERFF filing memorandum breaks out a rate change by component, catastrophe model update, frequency change, severity shift, reinsurance cost pass-through, that actuarial support documentation lives in SERFF.
I spent nine years working the desk at an independent agency before moving to writing. The SERFF filing is not a press release; it’s the source document. When a carrier’s public statement says “claims inflation drove the increase” and the SERFF filing shows that 6 of the 9 percentage points are attributable to a Verisk severe convective storm model update, the filing tells the real story. It contains underwriting strategy, pricing assumptions, catastrophe model vendor references, and loss ratio targets that carriers do not publish anywhere else. If hackers had obtained SERFF access, that data would represent a comprehensive map of every carrier’s forward-looking pricing posture across all 50 states.
NAIC’s investigation found they didn’t get it. That determination matters. But the fact that ShinyHunters specifically named SERFF in its claims, suggesting the group understood what it was worth, is notable on its own.
The Communication Gap Is the Real Story
NAIC discovered the breach on June 11. Its first public post appeared June 17, six full days later.
The National Association of Mutual Insurance Companies (NAMIC) sent a formal letter to NAIC President Scott White criticizing this directly. NAMIC wrote that the NAIC “did not seem to provide any type of directed alert other than what was posted on the NAIC website, did so nearly one full week after identifying the event occurred, and did not follow similar standards imparted onto insurers for responding to cybersecurity events.” The American Property Casualty Insurance Association (APCIA) sent its own letter, asking for “clear direction from NAIC” so APCIA could advise member companies on the scope and implications.
This is a fair criticism with a specific edge: state insurance regulators routinely require carriers to notify the relevant state DOI and affected parties within 30, 60, or 90 days of a data breach, depending on the state. The NAIC’s own model data security law, adopted by multiple states, sets notification standards. The NAIC took six days to post a note on its own website, without direct alerts to the carriers and state regulators whose data sits on NAIC systems.
The FBI is now involved, which is the appropriate response. Outside counsel and a third-party cybersecurity firm are engaged. The investigation into what exactly was posted could take several weeks, NAIC said.
What the Breach Actually Contained
Based on the June 25 update, the confirmed data in the published dataset includes two categories: publicly available statutory financial statements (already accessible through state websites and InsData before the breach) and credit rating agency data, specifically rating determinations of insurer investments. That second category is the more sensitive piece. Rating agency determinations of insurer investment portfolios are not routinely public, and carriers use them in regulatory solvency filings. The scope of what ShinyHunters actually holds from those credit files, versus what the group has claimed, is still being assessed.
ShinyHunters separately claimed to have 45,000 files from AM Best, Moody’s, Fitch, S&P, Kroll, DBRS, and Egan-Jones. NAIC says it does not believe the group holds the volume or scope of data it has claimed publicly. The discrepancy between what the group advertised (3.1TB, SERFF and all major regulatory systems) and what NAIC’s forensics found (statutory financials and credit rating data) follows a familiar ransomware playbook: inflate the claim to maximize leverage before the deadline, then walk back the “AI-generated misinterpretation”, ShinyHunters’ own phrasing, after the data goes live.
What This Means for Homeowners Shopping Coverage
For homeowners currently in the best home insurance companies market, nothing in your policy, your dec page, or your claim history was exposed. NAIC confirmed that policyholder data was not accessed. State insurance department systems, including the CDI in California, the OIR in Florida, and the TDI in Texas, were unaffected.
The real-world implication sits at the carrier and regulator level. If the investigation ultimately finds that any portion of confidential rate filing data was exposed, the competitive sensitivity is significant, carriers in active rate filing negotiations with state DOIs would face questions about whether their pricing assumptions are now visible to competitors. The NAIC’s assurance that SERFF was not breached forecloses that risk for now. Carriers should verify with their own counsel whether any data they submitted to NAIC systems over the policy years covered by the breach falls within what was accessed.
The broader takeaway is structural. The NAIC operates as the technology backbone for state-based insurance regulation, collecting data, running SERFF, processing premium tax filings, managing producer licensing systems. It is a high-value target for exactly the kind of data-aggregation attack ShinyHunters runs. The organization now has a documented incident on record, a formal response underway, and two industry trade associations on record demanding better communication standards. Whether the NAIC’s post-incident conduct meets the bar its own model laws set for carriers is a question regulators in participating states should be asking directly.
