NAIC Says Data Taken in Hack Has Been Published Online

 The National Association of Insurance Commissioners (NAIC) now says data taken earlier this month from its information technology systems has been published online by the hackers responsible.



Editor’s Note: This story was updated June 30 to include statements from Nationally Recognized Statistical Ratings Organizations.

In a short note posted midday June 25, NAIC said it was “actively working with an external cybersecurity partner to compare the scope and type of data the group posted with our own analysis.”

Later June 25, NAIC posted another update and, based on its review with an outside data consultant, the data posted includes publicly available statutory financial reporting information as well as credit rating agency data, including rating determinations of insurer investments.

NAIC said this data does not include any rating agency investment rationale reports.

S&P Global and Moody’s have said they suspended data feeds to NAIC. S&P said it remains in contact with the association. Both rating firms, as well as Fitch Ratings, said the NAIC incident did not affect their systems. Fitch said its “business operations are unaffected by this data breach at the NAIC.”

KBRA (Kroll Bond Rating Agency) issued a statement that it also suspended its data feed to NAIC “pending satisfactory resolution of the cybersecurity issues identified by the NAIC and a better understanding of the safeguards that will be implemented to prevent a recurrence.”

Insurance industry financial strength rating agency AM Best confirmed only data available to the public was comprised.

Other data impacted by the hack potentially includes routine technical information, such as outdated logs or configuration information, NAIC continued.

NAIC said a complete assessment will take “at least several weeks” but right now there is no evidence that personal identifiable information (PII) or payment or financial account information was impacted.

The support organization for state insurance regulators said it is “committed to transparency as this work proceeds.” NAIC’s regulatory filing systems are operating and secure, it added.

According to multiple online resources, the ShinyHunters ransomware group claimed responsibility for the NAIC breach, and allegedly stole 3.1 terabytes of data. The NAIC breach was part of a mass-hacking campaign of Oracle’s PeopleSoft software, which is used by thousands of organizations.

The group said it had technology provided by the NAIC, including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins), Uniform Certificate Authority Application (UCAA), Enterprise Data Platform (EDP), and Regulatory Data Collection (RDC). However, outside cybersecurity experts involved in an analysis of the breach confirmed this information was not taken, NAIC said.

No employee data, electronic funds transfer, risk-based capital data, policyholder information, producer data, or event registration payment information was accessed, the internal investigation concluded, NAIC added.

Đăng nhận xét

Mới hơn Cũ hơn

Support me!!! Thanks you!

Join our Team