July, 2026

The organization building insurers' AI exam tool got breached using the same tactics it exists to help regulators evaluate. Microsoft's biggest patch release in the program's history just landed, with two actively exploited flaws sitting in the identity and document infrastructure most policy admin and claims systems run on. And the market pricing this risk can't keep getting cheaper while it pays out more. This month is less about new threats than about whether the plumbing can keep up with them.

The organization building insurers' AI exam tool was breached itself

On June 24th, the National Association of Insurance Commissioners confirmed it was affected by a broad campaign exploiting a zero-day vulnerability in Oracle PeopleSoft, the same flaw Mandiant says hit more than 100 organizations, most of them educational institutions. The ShinyHunters group claimed responsibility and posted data to a leak site, later escalating the claim to 3.1 terabytes across more than 105,000 files. NAIC pushed back hard on the scope: it says PeopleSoft is used only for internal financial reporting, that no policyholder data, producer data, or state insurance department systems were touched, and that the incident was contained within about two weeks of its June 11th detection. Credit rating agencies Moody's and KBRA paused data feeds to NAIC out of caution; AM Best and Fitch said their own systems were unaffected.

What insurance leaders should care about:

NAIC supplies the data and analytical infrastructure behind SERFF, OPTins, and the AI Systems Evaluation Tool itself. This incident doesn't change what that tool asks of you, but it's a live example of the gap between what a threat actor claims and what's actually confirmed, exactly the discipline your own incident communications need when you're the one notifying a regulator. NAIC's phased, evidence-based public updates are a reasonable model for how to talk about a breach before every fact is in.

The largest Patch Tuesday on record just hit the identity and document systems insurers run on

Microsoft's July 2026 Patch Tuesday release fixed 622 unique vulnerabilities, the largest single release in the program's history, including three zero-days, two of them already under active exploitation, and more than 60 rated critical. CrowdStrike put the volume at roughly triple June's count and nearly five times May's. Two of the actively exploited flaws sit in infrastructure most insurers run daily: CVE-2026-56155, an elevation-of-privilege bug in Active Directory Federation Services, the identity system that underpins single sign-on across policy admin, claims, and agency management platforms; and CVE-2026-56164, an unauthenticated Microsoft SharePoint Server flaw. A separate pair of SharePoint remote-code-execution bugs, rated 9.8, requires no authentication or user interaction to exploit.

What insurance leaders should care about:

May's brief flagged AI's growing ability to find and weaponize software flaws faster than organizations can patch them, and CISA's discussion of compressing remediation windows to as little as three days. This month's patch volume is the number behind that warning: nearly five times May's vulnerability count in a single release, arriving faster than most 30- to 90-day patch cycles can absorb. AD FS and SharePoint are not edge systems. They are identity and document infrastructure that touches underwriting files, claims records, and producer portals across the industry. Confirm your patch management program can prioritize actively exploited, identity-adjacent vulnerabilities within days rather than your standard cycle, and confirm AD FS specifically is patched and monitored given its role as a pivot point for lateral movement.

An MGA and an insurance agency are the latest entities notifying regulators

AssuranceAmerica, an Atlanta-based managing general agency with roughly 9,500 agents writing personal auto, renters, and commercial auto policies across 14 states, began notifying customers in late June about a breach first detected March 17th after an attacker targeted a single employee. The investigation, only completed after three months, found names, driver's license numbers, Social Security numbers, and claims and policy information among the files copied. Separately, on July 4th the Play ransomware group listed Silvestri & Associates Insurance on its leak site, threatening to publish data if the agency doesn't negotiate.

What insurance leaders should care about:

Last month's brief flagged brokers and adjusters joining carriers on leak sites. This month's entrants are an MGA and an agency, reinforcing that policy size and license type don't determine target selection; access does. The more instructive detail is AssuranceAmerica's timeline: three months between detection and a completed investigation. That's the number your own breach counsel and forensics retainer should be stress-tested against. If your incident response plan assumes a faster timeline than that, confirm it's realistic before you need it.

NAIC regulators get their first formal pilot progress readout this week

The NAIC's Big Data and Artificial Intelligence Working Group holds a public meeting on July 22nd, its first session structured specifically to receive an update on how the AI Systems Evaluation Tool pilot is performing, roughly five months into the 12-state run that began in March and closes in September. Carriers in several pilot states, including California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin, have already received information requests tied to the tool's exhibits on AI governance, data integrity, and third-party risk. Trade groups objected early on that the pilot was voluntary for regulators while compulsory for companies; whatever regulators report this week will shape what gets tested before the tool is revised in September and October and brought back for a possible adoption vote at the Fall National Meeting in November.

What insurance leaders should care about:

This is no longer a future-exam-readiness exercise. If you write business in any of the 12 pilot states, this week's session is the first real signal of how the tool is landing in practice, before it gets revised for a second look ahead of a full-adoption vote. The gap most likely to surface first is contractual: vendor agreements for AI-driven underwriting or claims tools often predate these expectations and don't include rights to model documentation, bias-testing results, or performance data. Renegotiating those terms takes months your response window won't give you. Check your top AI vendor contracts now, not after the pilot closes.

State privacy law is now targeting the exact data telematics and UBI programs collect

Last month's brief flagged a state's suit against a national auto insurer over an SDK collecting driving-behavior and location data without consent. July adds a broader trend: Virginia's ban on the sale of precise geolocation data took effect July 1st, joining similar prohibitions already in place in Maryland and Oregon, with Connecticut's version following October 1st. Connecticut also enacted a new data broker law, effective October 1st, that separately bans surveillance pricing outright. New Jersey enacted what's being called the nation's most expensive data broker law on June 30th, with registration fees running up to $1.5 million annually, written broadly enough to reach companies with direct customer relationships, not just conventional third-party data brokers.

What insurance leaders should care about:

Usage-based insurance and telematics programs sit squarely inside this trend, not adjacent to it. A location-based pricing model or a driving-behavior discount program can trigger geolocation-sale restrictions in multiple states even when the insurer never intended to “sell” the data in a traditional sense; many of these statutes define “sale” broadly enough to capture data-sharing and licensing arrangements with analytics vendors. Map every telematics, UBI, or location-based program against this specific set of restrictions, not just your general privacy policy.

Trend Signal

AM Best's Q1 2026 cyber market report puts the U.S. cyber insurance loss ratio at 53 for 2025, the first time it's topped 50 since the pandemic-era ransomware spike, while pricing logged its eighth consecutive quarter of declines and third-party claims trended up 30%. Surplus lines carriers, who now write nearly two-thirds of all cyber premium, already carry a loss ratio near 56.

What insurance leaders should care about:

A market can't keep discounting a risk that's getting more expensive to pay out. Falling price, rising loss ratio, and a longer-tail claims category growing fastest is the setup for a hard-market correction, not a soft one that continues indefinitely. If you underwrite cyber, plan for that correction now. If you buy cyber coverage, expect underwriting scrutiny to tighten before pricing does.

Priority Actions for Insurance Leaders (Next 60 Days)

Priority 1 — Set a faster patch SLA for identity-adjacent, actively exploited vulnerabilities.

This month's record-setting patch volume shows why a flat 30- to 90-day cycle no longer works. Set a shorter, separate SLA for vulnerabilities that are both actively exploited and touch identity infrastructure like Active Directory Federation Services and confirm your team can act on it within days, not at your next scheduled maintenance window.

Priority 2 — Check your AI vendor contracts ahead of this week's NAIC pilot update.

If you write business in any of the 12 pilot states, don't wait for the tool's next revision to find out where the gaps are. Pull your underwriting and claims AI vendor contracts now and confirm they give you access to model documentation, bias-testing results, and performance data, not just a service description.

Priority 3 — Map telematics and UBI programs against geolocation-sale restrictions.

Treat this as a data-flow exercise, not a policy update. Identify every program that shares location or driving-behavior data with an analytics vendor or other third party and confirm none of those arrangements meets the broad “sale” definitions now in effect in Virginia, Maryland, and Oregon, with Connecticut following in October.

The regulator building the AI exam tool got breached. The largest patch release in Microsoft's history just landed in the identity systems insurers run on. And the market pricing all of this can't keep getting cheaper while it pays out more. None of the three is a reason to panic. All three are reasons to check your own documentation, and your own patch cycle, before someone else does.

→ If you can't show, right now, when your last AI vendor contract was reviewed against NAIC's evaluation criteria, or how long your data retention schedule holds sensitive records, those are the two questions an examiner will ask first.

FiveM helps insurers build, document, and continuously test regulator-ready governance programs, so the answer to an examiner's question is already on file..

Schedule a 30-Minute Call
 

Your partner in insurance transformation — strategy, modernization, and growth, delivered as a partnership.

facebook logo

Our mailing address is:
200 Central Ave, Suite 400 St. Petersburg, Florida 33701

Want to change how you receive these emails?
You can unsubscribe from this list.