FBI removes Accenture contractor after unapplied patch led to ShinyHunters breach

The FBI says the breach that exposed data on thousands of its employees happened because a third-party contractor never applied a security patch that had already been issued.

FBI removes Accenture contractor after unapplied patch led to ShinyHunters breach

At a glance

  • The FBI removed the Accenture contractor responsible for the PeopleSoft platform behind the breach
  • Cyber division assistant director Brett Leatherman blamed a security patch the contractor failed to deploy
  • Mandiant found ShinyHunters bypassed a WAF rule for CVE-2026-35273 using URL encoding
  • Two ShinyHunters members have been arrested and the FBI expects more

The FBI has removed an Accenture contractor over its role in the breach that exposed personal data on thousands of bureau employees, according to The Hacker News, which reported the development on 6 October 2026 citing Reuters. The bureau says the intrusion traces back to a security patch that was issued for the third-party-managed Oracle PeopleSoft platform but never applied.

What happened

The extortion group ShinyHunters compromised the FBI's job application portal by exploiting a flaw in Oracle PeopleSoft, The Hacker News reported. The platform was managed by a third-party organisation rather than by the bureau itself.

Brett Leatherman, assistant director of the FBI's cyber division, said in a statement quoted by the publication that "the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch" that had explicitly been issued. The bureau added that it has "removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce," and that the investigation continues with law enforcement partners.

Accenture told Reuters it remains "proud to support the mission of the FBI and will continue to do so," according to the same report. The company did not address the patch question in the quoted statement.

Technical details

The Hacker News cited Mandiant analysis showing that ShinyHunters did not simply walk through an unprotected flaw. The attackers bypassed a web application firewall rule that had been put in place to block requests to PeopleSoft's Environment Management Hub (PSEMHUB) endpoint, the entry point for CVE-2026-35273. According to that analysis, URL-encoding the request was enough for the WAF rule to miss the traffic while the PeopleSoft server still processed it normally.

That detail matters for defenders: the filtering rule was treated as the fix, and the actual software patch was left undeployed. The group reached the vulnerable endpoint through a variant the rule did not recognise.

Who is affected

The report describes thousands of bureau employees whose personal information was exposed; it does not give a precise figure or a full list of the data categories involved. The breach became public in September 2026 when ShinyHunters claimed the intrusion, and the bureau has been working through notification and remediation since.

On the law enforcement side, two ShinyHunters members have been arrested as of this reporting and the FBI indicates further arrests are likely, according to The Hacker News.

What to do

Organisations running Oracle PeopleSoft should verify that the patch for CVE-2026-35273 is actually installed rather than assuming a perimeter rule covers it, and should treat WAF signatures as a temporary measure only. Where a filtering rule is in place, test it against URL-encoded and otherwise obfuscated variants of the blocked path. The PSEMHUB endpoint should not be reachable from the public internet.

The wider lesson sits in contract management. Where patching is delegated to a supplier, organisations should require evidence that specific advisories were applied — version output, scan results, change records — rather than a status report, and should be able to verify that evidence independently.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.