Wednesday, October 7, 2026

News, explained by people who know.

Tech

FBI Removes Accenture Contractor After Missed Patch Opened Door to Employee Data Breach

The FBI has removed an Accenture contractor after concluding that a security patch left uninstalled on an Oracle PeopleSoft system allowed hackers to steal sensitive data on thousands of bureau employees.

By 3 min read
The J. Edgar Hoover Building, FBI headquarters, in Washington, D.C.
The J. Edgar Hoover Federal Bureau of Investigation (FBI) headquarters in Washington, D.C.

WASHINGTON, Oct. 6 (TodayViralUSA) — The FBI has removed a contractor working for Accenture after concluding that a security update left uninstalled on a third-party platform allowed hackers to steal sensitive personal information on thousands of bureau employees.

The bureau’s cybersecurity chief, Brett Leatherman, confirmed the removal of an unnamed contractor on Tuesday, a day after Reuters first reported it. “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said in a statement to Nextgov/FCW.

The FBI said it had taken steps to reduce further risk and protect its workforce. The statement is the bureau’s clearest account so far of how the intrusion happened, though it did not explain why the fix was missed or how the contractor’s work was supervised.

PeopleSoft weakness exploited

The cybercrime group ShinyHunters claimed responsibility for the hack last month. According to a person familiar with the matter cited by Nextgov/FCW, Accenture is responsible for patch management and custom code maintenance at the FBI, and the attackers got in through Oracle’s PeopleSoft human-resources software, for which Oracle had supplied the security patches that were never applied.

Google’s Mandiant unit recently reported that ShinyHunters had resumed widespread exploitation of a PeopleSoft vulnerability that Oracle patched in June.

Accenture said in a statement that it is “proud to support the mission of the FBI and will continue to do so.” The individual contractor has not been identified.

Counterintelligence concerns

The stolen records include employees’ home addresses, phone numbers and details about their spouses, as well as information on staff in intelligence and surveillance roles and private medical records, according to reports. Security experts warn that foreign intelligence services could use such data to identify personnel working on sensitive cases and to target them.

ShinyHunters has said it will not publish the data but has not said it deleted the files. Retired Lt. Gen. Robert Skinner, a former director of the Defense Information Systems Agency, told Nextgov/FCW that the group could still sell some or all of the information to foreign spy services or other buyers.

Law enforcement has moved against suspected members of the group in recent days. Dutch police announced the arrest of an alleged leader last week, and Reuters reported on Saturday that another suspected member had been detained in Jordan and was helping investigators track down other hackers.

We are committed to accuracy. Editorial Standards · Report a correction

Join the conversation

Leave a Reply

Your email address will not be published. Required fields are marked *

The Morning Viral

The day's biggest stories plus one expert take, in your inbox every morning.

Get notified at launch

No spam. Unsubscribe anytime. Privacy Policy