Full Breakdown
FBI Removes Accenture Contractor After Unpatched PeopleSoft Breach
By Drooid · · How we work
Core Incident
On October 5, 2026, the FBI terminated an Accenture contractor after a breach exposed personal details of thousands of FBI employees. The breach stemmed from a failure to apply a security patch to Oracle’s PeopleSoft human-resources platform that hosts the agency’s job-site infrastructure.
Background & Context
On June 10, Oracle issued a security alert for a critical PeopleSoft vulnerability (CVE-2026-35273) and urged immediate patching. That month, Google warned of a ShinyHunters campaign targeting PeopleSoft users.
On September 22, ShinyHunters claimed it had breached the FBI’s job portal by exploiting the PeopleSoft flaw, releasing a sample of roughly 5,000 records that included names, addresses, Social Security numbers, job assignments and some family-member details. The group said the operation was retaliation for a May 2026 advisory warning against ransom payments.
Data & Statistics
- The breach affected “thousands” of FBI personnel; ShinyHunters cited about 5,000 records.
- Exposed data included employee names, addresses, phone numbers, Social Security numbers, counter-intelligence job descriptions, and medical or psychiatric records.
- The PeopleSoft vulnerability carries a CVSS 3.1 severity score of 9.8, indicating a critical risk of remote code execution without authentication.
Official Statements & Responses
- Brett Leatherman, the FBI’s cyber chief, said the incident resulted from a security failure on a platform managed by a third-party after a contractor failed to implement an explicitly issued patch. He added that the FBI removed the contractor and took steps to mitigate further risk.
- Accenture affirmed its pride in supporting the FBI’s mission and said it would continue to do so, while declining comment on the specific contractor or patch issue.
- Reuters identified the platform as Oracle PeopleSoft and the manager as Accenture, though the FBI’s public statement did not name either.
- ShinyHunters asserted the breach was motivated by a dispute over the May advisory rather than financial gain.
Impact and Significance
The exposure of operational information raises security risks beyond typical identity-theft concerns. Former FBI officials called the breach a “major blow” to the agency’s operational security and highlighted the difficulty of timely patch deployment when critical systems are outsourced.
Conflicting Reports & Gaps
- The FBI has not confirmed which specific vulnerability was exploited or the PeopleTools version in use.
- While ShinyHunters claims to have accessed the portal via the PeopleSoft flaw, the agency has not verified the technical details.
- The identity of the removed contractor remains undisclosed, and the FBI has not detailed additional remedial actions.
What’s Next
The FBI continues its investigation, working with partners to assess the full scope of the data exposure. A ShinyHunters suspect detained in Jordan is reportedly cooperating, which may clarify the breach’s extent. Officials indicated further arrests are possible as the probe proceeds.
