Ransomware victim disclosure
← All victimsNAIC.org
Claimed by Shinyhunters · listed 9 hours ago
Status timeline
- ListedJun 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Business Services
- Listed on leak site
- Jun 18, 2026
About the victim
AI dossier — public-source company profileThe National Association of Insurance Commissioners (NAIC) is a U.S. regulatory organization that provides tools, resources, and platforms for state insurance departments and regulators to set standards, manage filings, and oversee the insurance industry. It operates critical systems including InsData, Vision, SERFF, and other platforms used by all fifty state insurance departments and thousands of licensed insurers.
- Industry
- Insurance Regulation & Compliance
Attack summary
Severity: critical — Confirmed exfiltration of 3.1TB of highly sensitive regulatory and financial data affecting all fifty U.S. state insurance departments, thousands of insurers, and credit rating agencies. Exposure includes federal EINs, statutory financial statements, and regulatory filings—data of significant systemic importance to financial regulation and potentially enabling identity theft and fraud.Shinyhunters claims to have exfiltrated 3.1 terabytes of data (105,000+ files) from NAIC's INSData platform and related systems serving state insurance departments and insurers. The leaked data includes regulatory filings, statistical records, financial statements, and credit rating information belonging to NAIC, state regulators, and thousands of insurance companies.
Data the group says was taken
AI dossier — extracted from the leak post- 2.1 million insurer regulatory filing PDFs
- 40,000 quarterly statistical CSVs with federal EINs and company data
- 45,000+ licensed rating agency files (Moody's, Fitch, S&P, Kroll, DBRS, AM Best)
- CUSIP and ISIN identifiers
- Statutory annual and quarterly financial statements
- Premium and loss statistics
- HR Ratings master data
- InsData platform records
- Vision credit rating feeds
- SERFF, OPTINS, UCAA, EDP, RDC system data
What the group claims
Over 3.1 terabytes of National Association of Insurance Commissioners data (105,000+ files) was compromised across the INSData statistical platform, Vision credit rating feeds, SERFF, OPTINS, UCAA, EDP, RDC, and state insurance department reporting systems (NAIC, all fifty state insurance departments, and thousands of licensed insurers), including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company data, 45,000+ licensed rating agency files from Moody's, Fitch, S&P, Kroll, DBRS, and AM Best with CUSIP and ISIN identifiers, statutory annual and quarterly financial statements, premium and loss statistics, and HR Ratings master data. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim siteNAIC.org
Source
Indexed 9 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

