NAIC Says Data Taken in Hack Has Been Published Online

 The National Association of Insurance Commissioners (NAIC) now says data taken earlier this month from its information technology systems has been published online by the hackers responsible.


001 002 003 004 005 006 007 008 009


Editor’s Note: This story was updated June 30 to include statements from Nationally Recognized Statistical Ratings Organizations.


010 011 012 013 014 015 016 017 018 019 020

In a short note posted midday June 25, NAIC said it was “actively working with an external cybersecurity partner to compare the scope and type of data the group posted with our own analysis.”


Later June 25, NAIC posted another update and, based on its review with an outside data consultant, the data posted includes publicly available statutory financial rep


021 022 023 024 025 026 027 028 029 030

orting information as well as credit rating agency data, including rating determinations of insurer investments.


NAIC said this data does not include any rating agency investment rationale reports.


031 032 033 034 035 036 037 038 039

S&P Global and Moody’s have said they suspended data feeds to NAIC. S&P said it remains in contact with the association. Both rating firms, as well as Fitch Rati


ngs, said the NAIC incident did not affect their systems. Fitch said its “business operations are unaffected by this data breach at the NAIC.”


040 041 042 043 044 045

KBRA (Kroll Bond Rating Agency) issued a statement that it also suspended its data feed to NAIC “pending satisfactory resolution of the cybersecurity issues i


dentified by the NAIC and a better understanding of the safeguards that will be implemented to prevent a recurrence.”


046 047 048 049 050 051 052 053 054

Insurance industry financial strength rating agency AM Best confirmed only data available to the public was comprised.


Other data impacted by the hack potentially includes routine technical information, such as outdated logs or configuration information, NAIC continued.


Watch More Image Part 2 >>>

NAIC said a complete assessment will take “at least several weeks” but right now there is no evidence that personal identifiable information (PII) or payment or financial account information was impacted.


The support organization for state insurance regulators said it is “committed to transparency as this work proceeds.” NAIC’s regulatory filing systems are


operating and secure, it added.


According to multiple online resources, the ShinyHunters ransomware group claimed responsibility for the NAIC breach, and allegedly stole 3.1 terabytes of data. The NAIC breach was part of a mass-hacking campaign


of Oracle’s PeopleSoft software, which is used by thousands of organizations.


The group said it had technology provided by the NAIC, including the System for Electronic Rate and Form Filing (SERFF), Online Premium Tax for Insurance (OPTins),


Uniform Certificate Authority Application (UCAA), Enterprise Data Platform (EDP), and Regulator


y Data Collection (RDC). However, outside cybersecurity experts involved in an analysis of the breach confirmed this information was not taken, NAIC said.


No employee data, electronic funds transfer, risk-based capital data, policyholder information, producer data, or event registration payment information was accessed, the internal investigation concluded, NAIC added.

Đăng nhận xét

Mới hơn Cũ hơn

Support me!!! Thanks you!

Join our Team