NAIC Says Data Taken in Hack Has Been Published Online

 The National Association of Insurance Commissioners (NAIC) now says data taken earlier this month from its information technology systems has been published online by the hackers responsible.


055 056 057 058 059


Editor’s Note: This story was updated June 30 to include statements from Nationally Recognized Statistical Ratings Organizations.


060 061 062 063

In a short note posted midday June 25, NAIC said it was “actively working with an external cybersecurity partner to compare the scope and type of data the group posted with our own analysis.”


Later June 25, NAIC posted another update and, based on its review with an outside data consultant, the data posted includes publicly available statutory financial rep


064 065 066 067 068

orting information as well as credit rating agency data, including rating determinations of insurer investments.


NAIC said this data does not include any rating agency investment rationale reports.


069 070 071 072 073

S&P Global and Moody’s have said they suspended data feeds to NAIC. S&P said it remains in contact with the association. Both rating firms, as well as Fitch Rati


ngs, said the NAIC incident did not affect their systems. Fitch said its “business operations are unaffected by this data breach at the NAIC.”


074 075 076 077 078 079 080 081

KBRA (Kroll Bond Rating Agency) issued a statement that it also suspended its data feed to NAIC “pending satisfactory resolution of the cybersecurity issues i


dentified by the NAIC and a better understanding of the safeguards that will be implemented to prevent a recurrence.”


082 083 084 085 086 087 088 089 090 091

Insurance industry financial strength rating agency AM Best confirmed only data available to the public was comprised.


Other data impacted by the hack potentially includes routine technical information, such as outdated logs or configuration information, NAIC continued.


See more beautiful photo albums Here >>>


NAIC said a complete assessment will take “at least several weeks” but right now there is no evidence that personal identifiable information (PII) or payment or financial account information was impacted.


The support organization for state insurance regulators said it is “committed to transparency as this work proceeds.” NAIC’s regulatory filing systems are


operating and secure, it added.


According to multiple online resources, the ShinyHunters ransomware group claimed responsibility for the NAIC breach, and allegedly stole 3.1 terabytes of data. The NAIC breach was part of a mass-hacking campaign


of Oracle’s PeopleSoft software, which is used by thousands of organizations.


The group said it had technology provided by the NAIC, including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins),


Uniform Certificate Authority Application (UCAA), Enterprise Data Platform (EDP), and Regulator


y Data Collection (RDC). However, outside cybersecurity experts involved in an analysis of the breach confirmed this information was not taken, NAIC said.


No employee data, electronic funds transfer, risk-based capital data, policyholder information, producer data, or event registration payment information was accessed, the internal investigation concluded, NAIC added.

Đăng nhận xét

Mới hơn Cũ hơn

Support me!!! Thanks you!

Join our Team