Insurance Regulator Breached, Security Firm Insider Scandal, CEOs Demand Hours-Not-Days Recovery

Insurance Regulator Breached, Security Firm Insider Scandal, CEOs Demand Hours-Not-Days Recovery

June 29, 2026 · 42 min

About this episode

The episode discusses a significant data breach in the U.S. insurance industry and its implications for cybersecurity.

The group that holds the financial filings for the entire U.S. insurance industry just got cracked open, and 3.1 terabytes of its data landed on the dark web. The break-in came through a software bug nobody could have patched in time. If a central regulator can be hit this way, the vendors and partners holding your data can too. *The breach comes through trust. Survival comes through speed.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week's stories for the executives, owners, and operators who don't have time to keep up with cyber news but can't afford to be blindsided by it either. First, the NAIC, the body where insurers in all fifty states file their financials, confirmed attackers got in, and a crew called ShinyHunters claims it stole 3.1 terabytes and dumped the whole haul when the ransom went unpaid. The way in was a zero-day, a flaw with no fix available, sitting inside Oracle's PeopleSoft software that the NAIC ran. Here is the part that should worry every owner: after the breach, credit rating agencies cut their data feeds to the NAIC, which froze a routine industry function for everyone downstream. One vendor's bug became hundreds of companies'…

People in this episode

Hosts: Bryan Hornung, Randy Bryan, Reginald Andre

Topics covered

Keywords

Mentioned in this episode

Organizations: NAIC, Oracle, Huntress

Products: PeopleSoft

More episodes of Security Squawk - The Business of Cybersecurity

Explore listener stats, chart rankings, contacts and more on the Security Squawk - The Business of Cybersecurity podcast page.