READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FBI Fires Accenture Contractor After Unpatched Oracle Software Let Hackers Steal Employee Data

FBI Fires Accenture Contractor After Unpatched Oracle Software Let Hackers Steal Employee Data
The FBI confirmed it cut ties with an Accenture contractor who failed to install a security patch on an Oracle PeopleSoft system, letting the hacking group ShinyHunters steal personal, medical and psychiatric records on thousands of bureau employees. Oracle and Google warned about this exact vulnerability back in June. Nobody patched it in time, and the bureau is now cleaning up a mess a basic software update could have prevented.

A Missed Update, A Federal Breach

The FBI removed an Accenture contractor on Monday, October 5, after determining the contractor's failure to install a security patch opened the door for hackers to steal sensitive personal data on thousands of bureau employees, according to Reuters, which cited two sources familiar with the matter.

FBI cyber division assistant director Brett Leatherman put it plainly in a statement to Reuters: "Our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization, after a contractor failed to implement a security patch explicitly issued to secure the platform." He said the bureau "removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."

The FBI did not publicly name the platform or the contracting firm. Reuters' sources did: the platform was Oracle's PeopleSoft human resources system, and the contractor worked for Accenture. Accenture confirmed it was still working with the bureau but dodged every question about the contractor or the missed patch, telling Reuters only that it was "proud to support the mission of the FBI and will continue to do so." Oracle did not respond to Reuters' request for comment at all.

What ShinyHunters Got

The hacking group ShinyHunters claimed responsibility last month for breaking into the FBI's job application portal through the PeopleSoft flaw, according to the Reuters reporting carried by The Straits Times and U.S. News & World Report. The group said it held data on nearly all FBI agents and on civilians who had applied for jobs with the bureau.

Cybernews reported the stolen data included granular descriptions of named employees' counterintelligence assignments, street addresses of human intelligence operatives, and medical and psychiatric records of bureau workers. Former FBI officials described the breach to Reuters as a major blow to the bureau's operational security. If an adversary now has home addresses tied to undercover intelligence roles, that is a safety problem for real people, not just a data-privacy headline.

ShinyHunters told reporters the attack was retaliation, not extortion. The group said it wanted the FBI to correct a May advisory about its hacking methods and never demanded a ransom, according to The Next Web.

The Technical Hole Nobody Closed

Google's Mandiant unit, cited by The Hacker News and Cyber Security News, traced the intrusion to CVE-2026-35273, a flaw in PeopleSoft's Environment Management Hub component. Mandiant's analysis says ShinyHunters used a URL-encoding trick, essentially double-encoding a malicious request, to slip past a web application firewall rule that was supposed to block exactly this kind of attack. The firewall decoded the request once, saw nothing suspicious, and passed it along. The PeopleSoft server then decoded it a second time and ran the hidden payload.

That trick only works against a firewall standing in for a patch that was never applied. Oracle and Google both issued warnings in June urging anyone running PeopleSoft to install "all Critical Patch Updates, Critical Security Patch Updates and Security Alerts without delay," according to Reuters. Whoever was responsible for the FBI's job site evidently did not.

The coverage splits on attribution. The Hacker News, The Cybersecurity Guru and Rescana all treat the CVE-2026-35273 and PSEMHUB exploit chain as the confirmed cause of the FBI breach. Cybersecurity News is the one outlet that flagged the gap in that narrative: the FBI's own statement never names a CVE or confirms which specific flaw was exploited, and Reuters has separately said it could not verify ShinyHunters' own account of how it got in. The technical attribution comes from Mandiant's research, not from the FBI. That distinction matters when assigning blame for exactly what went wrong.

What Happens Next

Two ShinyHunters members have already been arrested, and the FBI says more arrests are likely as it works leads with partners, according to The Hacker News. The bureau has not identified the fired contractor by name, and Reuters said it could not independently determine the individual's current employment status.

Federal agencies hand enormous amounts of sensitive data to outside contractors every year. This breach is a reminder that the weakest link in that chain is whoever forgets to click "install update." Congress has not announced any hearing on federal IT contracting oversight tied to this incident. Whether lawmakers push for one, and whether Oracle ever explains why a known, patchable flaw sat open on a system holding counterintelligence staff data, remains unanswered.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
U.S. News & World ReportExclusive-Accenture Contractor Removed From FBI Following Damaging Data Breach, Sources Say
center
The Straits TimesFBI removes Accenture contractor after data breach incident | The Straits Times
unknown
RESCAFBI Data Breach Analysis: ShinyHunters Exploit Unpatched Oracle PeopleSoft CVE-2026-35273 Due to Third-Party Patch Failure – Rescana
unknown
CybernewsFBI data breach: Accenture contractor removed over missed patch | Cybernews
unknown
squawknewsFBI removes Accenture contractor after data breach exposed employee records
unknown
Cybersecurity NewsFBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees
unknown
The Next WebAccenture contractor removed from FBI after unpatched system led to breach
unknown
Hendry AdrianFBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
unknown
The Cybersecurity GuruFBI ShinyHunters Breach: PeopleSoft Flaw & WAF Bypass Explained | The CyberSec Guru