Hackers Exploit PeopleSoft Zero-Day to Breach NAIC, Claim 3.1 TB Data Theft
Hackers exploited a zero-day vulnerability in Oracle’s PeopleSoft software to breach the National Association of Insurance Commissioners, the coordinating body for U.S. state insurance regulators. The cyberattack utilized an unauthenticated server-side request forgery chain that escalated to remote code execution on the NAIC’s systems, according to a report posted Sunday. In the immediate aftermath, attackers published excerpts of stolen data and claimed they exfiltrated 3.1 terabytes of information.
The NAIC has not confirmed the scope of the data loss, and it remains unclear when the breach occurred relative to Oracle’s public advisory and patch release. The attackers reportedly had a working exploit before the vendor disclosed the flaw. Following the initial data dump, hackers posted an update claiming discrepancies in earlier leak claims were due to an AI-generated misinterpretation, noting the increasing role of artificial intelligence even in criminal operations.
From the sources (1 posts)
@lukolejnikCyberattack on NAIC, the U.S. state insurance regulators’ coordinating body. PeopleSoft zero-day was exploited - an unauthenticated SSRF-to-RCE chain. Apparently they had a working exploit before Oracle’s public advisory and patch. Attacker