FBI Removes Contractor After Missed Patch Led to ShinyHunters Breach

The FBI removed an Accenture contractor after a missed Oracle PeopleSoft patch was tied to a ShinyHunters breach exposing sensitive employee data.

Written By
Kezia Jungco
Kezia Jungco
Oct 6, 2026
3 minute read
The FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch was linked to a ShinyHunters breach.

The FBI removed an Accenture contractor after a missed Oracle PeopleSoft security patch was linked to a ShinyHunters breach. Source: mrkathika/Flickr, CC BY-SA 2.0

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A missed security patch on a third-party-managed FBI platform has now led to a contractor being removed from the bureau’s support team.

The FBI said its review found that a contractor failed to apply a security update to the affected platform. Reuters, citing two sources, identified the system as Oracle PeopleSoft and said Accenture managed it.

ShinyHunters said it exploited the system to breach the FBI’s jobs site, exposing sensitive personnel data and putting new attention on how outside vendors handle patching and compensating controls for critical government systems.

FBI points to missed patch in PeopleSoft breach

Reuters reported that the FBI removed the contractor after determining that the breach stemmed from a security failure on a platform managed by a third party. FBI Cyber Division Assistant Director Brett Leatherman said the contractor had “failed to implement a security patch explicitly issued to secure the platform.”

Two sources told Reuters that the platform was Oracle PeopleSoft and that Accenture was the organization managing it. The FBI did not publicly identify either company in its statement, and Reuters could not determine the contractor’s identity or current employment status.

Accenture said it was “proud to support the mission of the FBI and will continue to do so,” but did not address questions about the contractor or the missed patch.

Reuters also reported that Google had warned in June about a ShinyHunters-linked campaign targeting PeopleSoft users. Oracle issued a security alert the same day and urged customers to apply critical updates without delay.

ShinyHunters reportedly bypassed a PeopleSoft defense

The Hacker News, citing Google-owned Mandiant, reported that ShinyHunters was exploiting a bypass involving CVE-2026-35273.

According to Mandiant’s assessment, the attackers used a URL-encoding technique to get around a web application firewall rule designed to block access to the vulnerable PeopleSoft Environment Management Hub, or PSEMHUB, endpoint.

The report adds another layer to the patch failure. A defensive rule was in place, but the attackers were reportedly able to work around it while the underlying vulnerable software remained exposed.

Advertisement

Breach exposed sensitive FBI personnel data

The data involved went well beyond usernames or contact details. Reuters said that exposed information included descriptions of counterintelligence work, street addresses of human intelligence operatives, and medical and psychiatric records belonging to FBI personnel.

Quartz reported that affected records also involved current and former FBI agents, applicants, and family members. Former FBI official Cynthia Kaiser warned that the exposure could create a physical threat to agents and their families.

ShinyHunters also claimed it accessed FBI criminal justice and HR systems and said it targeted the bureau in retaliation for an FBI advisory about the group’s harassment tactics. Those claims have not been independently confirmed.

What security teams should take from the breach

The incident shows why compensating controls cannot replace patching when the underlying software remains vulnerable.

For security teams managing third-party platforms, the case points to three practical checks:

  • Confirm who owns patch deployment and verify completion rather than assuming an advisory was acted on.
  • Test WAF and filtering rules against encoding and normalization bypass techniques.
  • Treat HR and personnel systems as high-value targets because they can contain sensitive operational and personal information.

The FBI is still investigating the breach and ShinyHunters. The broader lesson is straightforward: security teams need to verify that critical patches are actually applied, not assume a WAF rule or third-party service provider has reduced the risk enough. In this case, the missed patch remained the decisive gap.

Related reading: ShinyHunters previously claimed it breached FBI systems using an Oracle PeopleSoft zero-day, sharing 5,000 records as evidence and exposing sensitive employee and applicant data.

Advertisement


Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.