The Federal Bureau of Investigation has removed an Accenture contractor from work tied to a sensitive human resources platform after the contractor failed to apply a security patch, a lapse that the ShinyHunters hacking group exploited to steal personal data on thousands of bureau employees, two sources familiar with the matter told Reuters. A senior FBI official confirmed that an unidentified contractor had failed to properly patch the system they were responsible for, and the bureau has declined to name either the platform or the third party involved.
Reuters reported on October 5 that the platform at the centre of the case was Oracle's PeopleSoft, a human resources suite used across government and industry, and that the third party responsible for managing it was Accenture. The story, by Jana Winter and Raphael Satter, cited two sources familiar with the matter. Accenture said in a statement that it was proud to support the mission of the FBI and would continue to do so.
The intrusion became public in September, when ShinyHunters claimed it had broken into FBI systems, defaced the bureau's public jobs website and downloaded between two and three terabytes of data covering current and former employees as well as job applicants. The group posted a sample of 5,000 records that it said came from the breach, and the material included names, home addresses, phone numbers, dates of birth, and in some cases information about employees' spouses. ShinyHunters said the operation was not about money and framed it as retaliation for what it called inaccuracies in an FBI public service announcement.
The case has pushed Oracle's PeopleSoft platform into a wider argument about enterprise software that holds payroll, applicant, health and personnel records. PeopleSoft is not a niche product. It underpins HR and finance operations at universities, agencies and large companies, and the same class of flaw that features in the FBI case was used against other organisations earlier in 2026.
Key Facts
FBI cyber chief Brett Leatherman said: 'To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization after a contractor failed to implement a security patch explicitly issued to secure the platform. As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.' The removal took place on Monday, October 5, 2026, according to the two sources, and the contractor has not been publicly named.
What was taken matters as much as how. According to Reuters, the exposed material included granular descriptions of named employees' counterintelligence jobs, the street addresses of human intelligence operatives, and the medical and psychiatric records of bureau workers. Infosecurity Magazine reported on September 23 that ShinyHunters claimed to have hit the FBI through a zero-day exploit and shared a 5,000 record sample with 404 Media, and that the group's stated goal was to force the bureau to take down or amend a public service announcement published on May 15 rather than to extract a ransom.
The Hacker News reported on October 6 that Mandiant, the Google owned security firm, assessed that ShinyHunters was exploiting a bypass for CVE-2026-35273 by using a URL encoding trick to get around a web application firewall rule designed to block the vulnerable Environment Management Hub, or PSEMHUB, endpoint. That outlet also carried Accenture's statement that it was proud to support the FBI's mission. Two ShinyHunters members have been arrested, and the bureau has warned that more arrests are likely.
The Beltway Report reported on September 22 that the group defaced the FBI jobs website and claimed the site had been seized. In its own statement, ShinyHunters said it held data on all FBI employees and applicants, that it had reached HR, MedLink and Criminal Justice Information Services systems, and that the entry point was a zero-day in Oracle PeopleSoft that led to FBI managed AWS GovCloud servers. Between May and June 2026 the same group exploited a PeopleSoft Environment Management component zero-day against more than 100 organisations, mostly universities. In June, Google raised the alarm over the campaign and Oracle issued a security alert identifying a PeopleSoft weakness and urging customers to apply all Critical Patch Updates, Critical Security Patch Updates and Security Alerts without delay.
The Verge reported on October 6 that ShinyHunters claimed last month to have used the HR platform to access data on all FBI employees and applicants, and it tied the removal of the Accenture worker directly to the missing patch. The FBI has not published an incident timeline and has not said how many people were ultimately affected beyond characterising the figure as thousands.
Analysis
The bigger picture here is that the most damaging data loss to hit the FBI in recent memory did not come from a failure of the bureau's own security stack. It came from a patch that somebody else was responsible for installing on a platform that somebody else was responsible for managing. Leatherman's phrasing is unusually precise for a government statement: the patch was explicitly issued, and it was not implemented. That turns a technical question into a contractual and accountability question, and it is the reason a personnel decision, rather than a systems upgrade, became the headline.
A second judgement follows from the record. The apparent contradiction between ShinyHunters claiming a zero-day and the FBI describing a missing patch is less a dispute than a timeline. Oracle flagged a PeopleSoft weakness and shipped fixes in June, and Mandiant's assessment points to a firewall bypass against a known vulnerable endpoint tracked as CVE-2026-35273. An attacker who reaches an endpoint for which a vendor has already published mitigations is not a mystery. It is a maintenance failure with a named cause, and the fact that the group could reach FBI managed cloud infrastructure from there is the part that will be studied for years.
The commercial logic is not complicated. Human resources and enterprise resource planning systems concentrate exactly the data that is hardest to replace: identity records, family details, payroll, medical notes and, in this case, job descriptions that describe what people do for a living in national security. Steve Povolny, vice president of AI strategy and security research at Exabeam, described the earlier education sector victims as collateral damage from a failed shot at the bureau and said ShinyHunters is systematically mining ERP platforms that hold HR, payroll, applicant and health data. The FBI case is the same method applied to a target the group clearly wanted.
Why It Matters
The stolen files are not credit card numbers. Granular descriptions of named employees' counterintelligence work, the street addresses of human intelligence operatives and psychiatric records together form a map of people whose identities are supposed to be protected. For an agency whose workforce depends on a degree of anonymity in certain roles, that exposure cannot be undone by a password reset. It is the kind of material that stays sensitive for the rest of a career.
The case also sets a marker for how the United States government handles third party risk. A federal agency has publicly stated that a security failure on a contractor managed platform caused an incident affecting thousands of its employees, and it has responded by removing the contractor. Every other agency and company running PeopleSoft, and every vendor managing one on somebody else's behalf, is now measuring its own patch records against that standard.
Finally, the disclosure shows how quickly an unpatched enterprise application can become a national security story. The flaw was not exotic. The fixes existed. What failed was the process that was supposed to make sure they were installed.
Next Up
The investigation is continuing. A key ShinyHunters suspect was detained in Jordan and is cooperating with authorities, two members of the group have already been arrested, and the FBI has said more arrests are likely. The bureau has also said it has taken steps to mitigate further risk and protect its workforce, without detailing what those steps are.
For everyone else running Oracle PeopleSoft, the recommended mitigations are already on the record: apply the patch for the earlier flaw, disable the Environment Management Hub or remove the PSEMHUB application, take PeopleSoft administrative and integration interfaces off the internet, and hunt for suspicious POST activity in WebLogic logs. The lesson of this breach is that the last item on that list is the one that turns a patch notice into an actual defence.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.