FBI Removes Accenture Contractor After Missed Patch Linked to ShinyHunters Breach
The FBI removed an Accenture contractor after a missed security patch contributed to a ShinyHunters-linked breach that exposed sensitive personal information belonging to thousands of FBI employees.

The FBI has removed a contractor after determining that a failure to apply a security patch contributed to a major data breach that exposed sensitive information belonging to thousands of bureau employees.
Two sources familiar with the investigation told Reuters that the contractor worked for Accenture and that the affected platform was Oracle PeopleSoft, which was used in connection with the FBI's jobs portal. The FBI itself did not publicly identify either Accenture or PeopleSoft in its statement.
FBI Confirms Patch Management Failure
FBI cyber division assistant director Brett Leatherman said the bureau's review determined that the incident resulted from a security failure involving a platform managed by a third-party organization.
According to the FBI, a contractor failed to implement a security patch that had been explicitly issued to protect the platform.
The bureau subsequently removed the contractor and said it had taken measures to reduce further risk and protect its workforce.
The incident highlights a straightforward but potentially devastating attack path:
Security Patch Available → Patch Not Applied → Vulnerable Third-Party Platform Remains Exposed → Attackers Gain Access → Sensitive FBI Data Stolen
ShinyHunters Claims Responsibility
The cybercrime group ShinyHunters previously claimed responsibility for breaching the FBI's jobs website and said it exploited a vulnerability in PeopleSoft.
Reuters' sources identified Oracle PeopleSoft as the affected HR platform, but Reuters noted that it had not independently established every technical detail of the attackers' claimed entry route.
Google-owned Mandiant has separately reported ShinyHunters-linked exploitation involving a bypass for CVE-2026-35273, where URL encoding could be used to evade a web application firewall rule intended to block access to a vulnerable PeopleSoft Environment Management Hub endpoint.
It is therefore important not to state conclusively that CVE-2026-35273 was the exact vulnerability used against the FBI unless further official technical findings confirm that connection.
Highly Sensitive FBI Employee Data Exposed
The breach exposed sensitive personal information associated with thousands of FBI personnel.
Reuters reported that the compromised information included details such as:
- Descriptions of employees' counterintelligence work
- Street addresses associated with human intelligence personnel
- Medical information
- Psychiatric records
- Other sensitive employee information
The nature of this information creates risks beyond ordinary identity theft, potentially enabling highly targeted phishing, impersonation, harassment and social-engineering attacks against affected personnel.
Accenture Identified by Reuters Sources
The FBI described the responsible organization only as a third party.
However, two Reuters sources identified that organization as Accenture.
Accenture told Reuters it was proud to support the FBI's mission and would continue doing so, but did not answer questions regarding the individual contractor or the alleged failure to deploy the patch.
Investigation Continues
The FBI is still assessing the overall impact of the breach and working with partners as part of its investigation.
The incident comes amid broader law-enforcement activity involving ShinyHunters. Authorities have recently detained individuals suspected of involvement with the cybercrime operation, while investigations into its activities continue.
Security Takeaway
The FBI incident demonstrates that sophisticated organizations can still suffer serious breaches because of a fundamental security-control failure: not applying an available patch.
It also highlights the importance of managing cybersecurity responsibilities across contractors and service providers.
Organizations should ensure that critical patches are not merely issued but independently verified as successfully deployed through:
Patch Identification → Risk Prioritization → Deployment → Verification → Vulnerability Rescan → Continuous Monitoring
For critical internet-facing platforms, organizations should also maintain clear ownership of patching responsibilities, enforce remediation SLAs and verify third-party compliance rather than assuming updates have been completed.
Related reporting
Denmark Says Attackers Accessed CPR Data of 8.8 Million People Through Company Account
Denmark investigates unauthorized access to CPR data linked to about 8.8 million people after attackers abused a private company's legitimate access to the national population register.
Rs. 2.87 Million Vanishes in 14 Minutes: Sri Lanka Banking Incident Raises Digital Fraud Questions
A Bank of Ceylon customer disputes 30 transactions totaling Rs. 2.869 million completed within 14 minutes. BOC says its systems were not breached, raising questions about credential theft, OTP security and digital banking fraud.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claims it breached FBI systems and stole sensitive data on agents, employees and job applicants, while the FBI investigates unauthorized activity affecting FBIJobs.gov.


