A missed security patch on a third-party-managed FBI platform has now led to a contractor being removed from the bureau’s support team.
The FBI said its review found that a contractor failed to apply a security update to the affected platform. Reuters, citing two sources, identified the system as Oracle PeopleSoft and said Accenture managed it.
ShinyHunters said it exploited the system to breach the FBI’s jobs site, exposing sensitive personnel data and putting new attention on how outside vendors handle patching and compensating controls for critical government systems.
FBI points to missed patch in PeopleSoft breach
Reuters reported that the FBI removed the contractor after determining that the breach stemmed from a security failure on a platform managed by a third party. FBI Cyber Division Assistant Director Brett Leatherman said the contractor had “failed to implement a security patch explicitly issued to secure the platform.”
Two sources told Reuters that the platform was Oracle PeopleSoft and that Accenture was the organization managing it. The FBI did not publicly identify either company in its statement, and Reuters could not determine the contractor’s identity or current employment status.
Accenture said it was “proud to support the mission of the FBI and will continue to do so,” but did not address questions about the contractor or the missed patch.
Reuters also reported that Google had warned in June about a ShinyHunters-linked campaign targeting PeopleSoft users. Oracle issued a security alert the same day and urged customers to apply critical updates without delay.
ShinyHunters reportedly bypassed a PeopleSoft defense
The Hacker News, citing Google-owned Mandiant, reported that ShinyHunters was exploiting a bypass involving CVE-2026-35273.
According to Mandiant’s assessment, the attackers used a URL-encoding technique to get around a web application firewall rule designed to block access to the vulnerable PeopleSoft Environment Management Hub, or PSEMHUB, endpoint.
The report adds another layer to the patch failure. A defensive rule was in place, but the attackers were reportedly able to work around it while the underlying vulnerable software remained exposed.
Breach exposed sensitive FBI personnel data
The data involved went well beyond usernames or contact details. Reuters said that exposed information included descriptions of counterintelligence work, street addresses of human intelligence operatives, and medical and psychiatric records belonging to FBI personnel.
Quartz reported that affected records also involved current and former FBI agents, applicants, and family members. Former FBI official Cynthia Kaiser warned that the exposure could create a physical threat to agents and their families.
ShinyHunters also claimed it accessed FBI criminal justice and HR systems and said it targeted the bureau in retaliation for an FBI advisory about the group’s harassment tactics. Those claims have not been independently confirmed.
What security teams should take from the breach
The incident shows why compensating controls cannot replace patching when the underlying software remains vulnerable.
For security teams managing third-party platforms, the case points to three practical checks:
- Confirm who owns patch deployment and verify completion rather than assuming an advisory was acted on.
- Test WAF and filtering rules against encoding and normalization bypass techniques.
- Treat HR and personnel systems as high-value targets because they can contain sensitive operational and personal information.
The FBI is still investigating the breach and ShinyHunters. The broader lesson is straightforward: security teams need to verify that critical patches are actually applied, not assume a WAF rule or third-party service provider has reduced the risk enough. In this case, the missed patch remained the decisive gap.
Related reading: ShinyHunters previously claimed it breached FBI systems using an Oracle PeopleSoft zero-day, sharing 5,000 records as evidence and exposing sensitive employee and applicant data.





