Skip to main content
The Wire
CyberNews by Zentrya One
Data Breaches

FBI Removes Accenture Contractor After Missed Patch Linked to ShinyHunters Breach

The FBI removed an Accenture contractor after a missed security patch contributed to a ShinyHunters-linked breach that exposed sensitive personal information belonging to thousands of FBI employees.

The FBI has removed a contractor after determining that a failure to apply a security patch contributed to a major data breach that exposed sensitive information belonging to thousands of bureau employees.

Two sources familiar with the investigation told Reuters that the contractor worked for Accenture and that the affected platform was Oracle PeopleSoft, which was used in connection with the FBI's jobs portal. The FBI itself did not publicly identify either Accenture or PeopleSoft in its statement.

FBI Confirms Patch Management Failure

FBI cyber division assistant director Brett Leatherman said the bureau's review determined that the incident resulted from a security failure involving a platform managed by a third-party organization.

According to the FBI, a contractor failed to implement a security patch that had been explicitly issued to protect the platform.

The bureau subsequently removed the contractor and said it had taken measures to reduce further risk and protect its workforce.

The incident highlights a straightforward but potentially devastating attack path:

Security Patch Available → Patch Not Applied → Vulnerable Third-Party Platform Remains Exposed → Attackers Gain Access → Sensitive FBI Data Stolen

ShinyHunters Claims Responsibility

The cybercrime group ShinyHunters previously claimed responsibility for breaching the FBI's jobs website and said it exploited a vulnerability in PeopleSoft.

Reuters' sources identified Oracle PeopleSoft as the affected HR platform, but Reuters noted that it had not independently established every technical detail of the attackers' claimed entry route.

Google-owned Mandiant has separately reported ShinyHunters-linked exploitation involving a bypass for CVE-2026-35273, where URL encoding could be used to evade a web application firewall rule intended to block access to a vulnerable PeopleSoft Environment Management Hub endpoint.

It is therefore important not to state conclusively that CVE-2026-35273 was the exact vulnerability used against the FBI unless further official technical findings confirm that connection.

Highly Sensitive FBI Employee Data Exposed

The breach exposed sensitive personal information associated with thousands of FBI personnel.

Reuters reported that the compromised information included details such as:

  • Descriptions of employees' counterintelligence work
  • Street addresses associated with human intelligence personnel
  • Medical information
  • Psychiatric records
  • Other sensitive employee information

The nature of this information creates risks beyond ordinary identity theft, potentially enabling highly targeted phishing, impersonation, harassment and social-engineering attacks against affected personnel.

Accenture Identified by Reuters Sources

The FBI described the responsible organization only as a third party.

However, two Reuters sources identified that organization as Accenture.

Accenture told Reuters it was proud to support the FBI's mission and would continue doing so, but did not answer questions regarding the individual contractor or the alleged failure to deploy the patch.

Investigation Continues

The FBI is still assessing the overall impact of the breach and working with partners as part of its investigation.

The incident comes amid broader law-enforcement activity involving ShinyHunters. Authorities have recently detained individuals suspected of involvement with the cybercrime operation, while investigations into its activities continue.

Security Takeaway

The FBI incident demonstrates that sophisticated organizations can still suffer serious breaches because of a fundamental security-control failure: not applying an available patch.

It also highlights the importance of managing cybersecurity responsibilities across contractors and service providers.

Organizations should ensure that critical patches are not merely issued but independently verified as successfully deployed through:

Patch Identification → Risk Prioritization → Deployment → Verification → Vulnerability Rescan → Continuous Monitoring

For critical internet-facing platforms, organizations should also maintain clear ownership of patching responsibilities, enforce remediation SLAs and verify third-party compliance rather than assuming updates have been completed.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.