Technology·News & analysis
FBI drops an Accenture contractor after a missed patch exposed staff data
A senior FBI official says a contractor failed to apply a security patch to a system it managed. Sources say it was Oracle's PeopleSoft and the contractor was Accenture, tying it to last month's ShinyHunters breach.

Tide
Wave
Sci-fi
1/10
Reality
Shipping
One skipped update, and the bureau's own files walk out the door.How we rate
The FBI removed a contractor, which sources say was Accenture, after a breach of bureau staff data that the FBI blames on a security patch that was never applied.
The extortion group ShinyHunters claimed last month it took data on agents and job applicants through Oracle's PeopleSoft. It shows how one missed update by an outside IT provider can expose even a law enforcement agency's own people.
What to know
- The FBI removed a contractor on Monday after a breach exposed personal data of thousands of bureau staff, Reuters reports.
- A senior FBI official said the contractor failed to apply a security patch to a system it managed. Two sources named the system as Oracle PeopleSoft and the contractor as Accenture.
- The extortion group ShinyHunters said last month it broke into the FBI's jobs portal through a PeopleSoft flaw and stole data on agents and applicants.
- Mandiant says ShinyHunters reworked an older PeopleSoft exploit to slip past firewall rules at organizations that hadn't installed Oracle's patch.
The FBI has cut ties with a contractor it blames for a breach of its own employees' data.
The bureau removed the contractor on Monday over its role in a breach that exposed personal details of thousands of FBI staff, Reuters reported, citing two people familiar with the matter. A senior FBI official said the contractor had failed to apply a required security patch.
The FBI didn't name the company. Reuters' two sources said it was Accenture, and the system was Oracle's PeopleSoft human resources platform, The Next Web reports.
What did the FBI say?
The bureau pinned the breach on a single missed fix.
A senior FBI official told Reuters that an unnamed contractor hadn't applied a security patch to a system in its care.
"As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce," the official said.
The FBI didn't name the company or the platform, and The Next Web said it hadn't independently verified the report.
What did Accenture say?
Not much.
Accenture told Reuters it was proud to support the FBI and would continue to do so. It didn't respond to questions about the contractor or the missed patch, according to The Next Web.
How does this connect to ShinyHunters?
Last month, the extortion group ShinyHunters said it had used a PeopleSoft flaw to break into the FBI's jobs portal.
What it claimed: the group said it held data on almost all FBI agents and on people who had applied to work for the bureau, The Next Web reports. ShinyHunters told The Register it had used an unspecified, unconfirmed Oracle PeopleSoft zero-day to breach the portals, according to Help Net Security.
How far it says it got: the group also claimed it breached FBI-managed servers on AWS GovCloud and stole personnel files on current, former and aspiring FBI employees.
Which systems: according to the BBC, the group claimed access to FBIJobs, FBI BEAST, which handles background checks on employees and applicants, FBI MedLink, which stores medical records, and FBI BICS, which contains investigative information, Help Net Security reports.
How much: ShinyHunters claimed in posts on the dark web and messages to media outlets that it stole 2 to 3 terabytes of data related to FBI workers, CBS News reports. Its claim to have data on every FBI employee hasn't been publicly verified.
Sensitive roles: among the stolen documents is one that "provides data on roles of FBI staff in little-known or sensitive FBI units," Reuters reported, according to Help Net Security. Reuters couldn't verify that all the job assignments were authentic or up to date. But it matched the career details or titles of eight people in the leaked data to court filings, news articles, LinkedIn profiles or posts on sites such as Instagram.
When it surfaced: the breach was first reported on September 22 by 404 Media, according to CBS News. The FBI confirmed it was investigating ShinyHunters' claim about employee data the same week, Help Net Security reported.
Why did the group do it?
It says it wasn't about money.
ShinyHunters described the attack as revenge, The Next Web reports. It targeted the FBI over a May advisory about the group's methods, and demanded the bureau correct the advisory instead of paying a ransom.
That advisory had told victim organizations not to pay ShinyHunters, Help Net Security notes. The group threatened to release the stolen information if the FBI didn't retract what it called "false allegations."
The FBI's online portals for job applicants and special agent applicants were still offline as of late September, Help Net Security reported.
How did attackers get past the defenses?
The exact route into the FBI hasn't been confirmed. But security researchers have documented how ShinyHunters attacks PeopleSoft.
The original flaw: in May and June, ShinyHunters exploited a PeopleSoft vulnerability, CVE-2026-35273, as a zero-day, mostly against academic institutions, according to Google Cloud's Mandiant, as reported by Help Net Security.
Oracle's advice then: apply the emergency patch, or if that wasn't possible, restrict network access to PeopleSoft servers to trusted internal networks.
The warning: "Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed," Mandiant said at the time.
The bypass: Mandiant now says ShinyHunters modified its exploit to get around firewall rules blocking the vulnerable endpoint. "The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path," Mandiant's analysts wrote. That let the group reach the endpoint on systems whose operators believed their firewall rules had mitigated the problem.
"The current campaign demonstrates that [ShinyHunters] adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability," Mandiant said.
The group has since expanded its targets to higher education, technology, IT services, healthcare, agriculture, transportation and government, according to Mandiant.
After getting in: once inside, the group deploys web shells and a legitimate remote management tool called MeshAgent, and runs commands without writing files to disk, Help Net Security reports, citing Mandiant. Using legitimate tools and fileless commands can make an intrusion harder to spot.
Not confirmed for the FBI: neither the FBI nor Reuters has said whether this same flaw was used against the bureau, The Next Web notes.
Has anyone been arrested?
The FBI says yes, more than one person.
"The Bureau continues to aggressively investigate the recent Cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects and we will spare no resource in bringing each of the responsible individuals to justice," the FBI said, according to CBS News.
A suspected member of the group was detained in Jordan and is cooperating with investigators, CBS News reports, citing US officials. Separately, Dutch police arrested a 24-year-old man in Amsterdam on September 15 on suspicion of being a member, days before the FBI breach was announced.
ShinyHunters told Reuters that the Amsterdam suspect had "no association" with the group, according to CBS News. It's unclear how many other alleged hackers may be involved, a US source told CBS News, and the FBI is still determining how far the damage from the breach goes, The Next Web reports.
Why it matters
Some former FBI officials have described the breach as a major blow to the bureau's operational security, according to Reuters.
The FBI's own explanation is that the weak point wasn't the bureau's network, but a patch that an outside contractor didn't install. Big organizations hand large parts of their IT to firms like Accenture, so a single missed update at a vendor can expose an agency's most sensitive people.
What it means for you
- If you run PeopleSoft: install Oracle's patch. Mandiant's research shows firewall rules alone didn't stop this group.
- If you rely on IT contractors: check who is responsible for patching each system, and verify it's actually done.
- If you applied to the FBI or work there: watch for official notices from the bureau, and be wary of phishing that uses your personal details.
The bottom line
The FBI removed a contractor, reportedly Accenture, after a missed PeopleSoft patch led to a breach of bureau staff data claimed by the extortion group ShinyHunters. The FBI says it has arrested multiple suspects, but the full scope of the damage is still being worked out.
Key facts
- Who acted
- FBI, on Monday, October 5
- Contractor
- Accenture, according to two Reuters sources
- System
- Oracle PeopleSoft HR platform, according to the same sources
- Cause
- A required security patch wasn't applied, the FBI says
- Claimed by
- ShinyHunters extortion group
Got questions?
Quick answers, plain wordsWhat did the FBI do?
It removed a contractor on Monday over its role in a breach that exposed personal data of thousands of FBI staff, Reuters reports, citing two people familiar with the matter.
Why was the contractor removed?
A senior FBI official told Reuters that the contractor didn't apply a security patch to a system in its care. 'As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,' the official said.
Was it Accenture?
The FBI didn't name the company or the system. Two sources told Reuters the platform was Oracle's PeopleSoft human resources system and the third party responsible for it was Accenture.
What did Accenture say?
Accenture told Reuters it was proud to support the FBI and would continue to do so, but didn't respond to questions about the contractor or the missed patch, The Next Web reports.
Who is behind the breach?
The extortion group ShinyHunters said last month it used a PeopleSoft flaw to break into the FBI's jobs portal. It said it holds data on almost all FBI agents and on people who applied to work for the bureau.
What data was taken?
ShinyHunters claims it took personal information on tens of thousands of FBI agents and prospective employees, plus medical information, Help Net Security reports. The group's claims haven't all been publicly verified.
Which PeopleSoft flaw was used?
That hasn't been confirmed. Mandiant says ShinyHunters has been exploiting CVE-2026-35273 again, after first using it as a zero-day against mostly academic targets in May and June. Neither the FBI nor Reuters has said whether that flaw was used here.
Why didn't firewall rules stop it?
Mandiant says ShinyHunters bypassed text-based firewall rules by URL-encoding a single character in the request path, reaching the vulnerable endpoint at organizations that relied on the firewall rule instead of patching.
Has anyone been arrested?
The FBI says it has worked with partners to arrest multiple subjects. CBS News reports a suspected member was detained in Jordan and is cooperating, and Dutch police arrested a 24-year-old man in Amsterdam on September 15 on suspicion of being a member.
What should organizations running PeopleSoft do?
Apply Oracle's patch. When the flaw was first exploited, Oracle advised the emergency patch and, if that wasn't possible, restricting network access to PeopleSoft servers. Mandiant warned that firewall body-inspection rules alone are insufficient.
SourcesThe Next Web
Topics and tagsCybersecurity, fbi, accenture, data breach
Related stories

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers
Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

A Pentagon records system was breached for 9 months before anyone noticed
The Defense Manpower Data Center disclosed that unauthorized users accessed unencrypted personal data on 2.76 million living and 294,000 deceased people between October 2025 and July 2026.

Dutch police arrest a security professional in the ShinyHunters hacking probe
Police arrested a 24-year-old Amsterdam man working in offensive security on suspicion of ties to ShinyHunters, the group behind some of the largest data breaches in recent years.
More in brief
- Fusion startup Type One Energy raises $200M to build a power plant by 2034Oct 6
- Qualcomm will license Huawei's patents, a reversal 25 years in the makingOct 6
- Google signs a deal to squeeze 890 MW more out of Constellation's nuclear plantsOct 6
- OpenAI apologizes to Australian lawmakers for its AI agent's Medicare website hackOct 6
- UK regulator Ofcom investigates Meta over Instagram's disappearing-photo feature InstantsOct 6
- South Korea's president says AI was likely used in a wave of bank hacksOct 6