NAIC Confirms Breach via Oracle PeopleSoft Zero-Day (infosecurity-magazine.com)
- Zero-day in Oracle PeopleSoft used to breach NAIC systems
- Exposed: public financial reports and credit rating data; no personal or payment data
- NAIC contained breach, involved FBI; operations restored except PeopleSoft payments
"The US National Association of Insurance Commissioners (NAIC) confirmed a data breach using a zero-day vulnerability in Oracle PeopleSoft. The attack was detected on June 11, disclosed on June 17, and updated on June 26. The attacker accessed certain data storage areas, exposing publicly available financial reports and credit rating agency data. No personal information of users or employees, payment data, or regulatory system data was compromised. The NAIC contained the breach, notified the FBI, and restored operations except for PeopleSoft invoice payments."
no comments yet.