> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> FBI Drops Accenture Contractor After Sensitive Data Breach

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 06/10/2026 09:27] [LANGUAGE: EN]
Accenture lost an FBI contract after a missed security patch exposed sensitive employee data, raising serious concerns over operational security. The FBI pulled an Accenture contractor off its account on Monday, and the reason is almost mundane compared to the damage it caused. One update didn’t get installed on time. “The ‌Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters.” Reuters reports. “The development comes as the FBI is still trying to ascertain the ramifications of the breach, ​which some former bureau officials have described as a major blow to the organization’s operational security.” Two sources told Reuters the bureau cut ties with the contractor over their role in a breach that exposed sensitive personal data on thousands of FBI employees. Former bureau officials are calling it a serious hit to the organization’s operational security, not just an embarrassing headline. That’s a strong statement coming from people who used to run the place. “To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform,” FBI cyber chief Brett Leatherman said in the statement to Reuters. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.” FBI cyber chief Brett Leatherman laid out exactly what went wrong in a statement to Reuters. The incident traces back to a platform managed by a third party, where a contractor “failed to implement a security patch explicitly issued to secure the platform.” Not an unknown flaw, not a zero day, a fix that already existed and just didn’t get installed. Reuters’ sources identified the platform as Oracle PeopleSoft, the human resources software running the FBI’s job site, and named Accenture as the third party managing it. Oracle hasn’t responded to requests for comment. Accenture, for its part, said only that it’s proud to support the FBI’s mission and plans to keep doing so, dodging every question about the contractor or the missed patch. In June, Google warned about a ShinyHunters-linked campaign targeting PeopleSoft users. On the same day, Oracle issued a security alert about the vulnerability and released a fix. Both companies told PeopleSoft customers to install all critical patches and security updates as soon as possible. ShinyHunters later said they used this same PeopleSoft vulnerability to access the FBI’s job site. Patching large enterprise systems can be difficult, but this wasn’t an unknown or obscure flaw. It had already been publicly identified, attackers were exploiting it, and a fix was available. In September, the popular cybercrime group ShinyHunters claimed that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead carried out in response to an FBI warning published earlier this year. The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it obtained data on a large number of current and former FBI personnel. The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details. Reuters was able to partially match some of the sample information with other records, including data associated with FBI Director Kash Patel. “Reuters was able to partially verify the authenticity of the information by running the details, including the Social Security numbers, ​against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs.” reads the report published by Reuters. “In at least 10 instances — including in the case ‌of FBI ⁠Director Kash Patel — Reuters found details that appeared to match. A person familiar with the matter said that the job descriptions in the data also matched in at least some cases.” The FBI acknowledged that it is aware of claims involving unauthorized activity affecting FBIjobs.gov and said it is investigating. The agency has not confirmed that its internal systems were compromised or that ShinyHunters obtained the data it claims to possess. ShinyHunters provided a possible technical explanation for the alleged intrusion. The group claims the exploitation of an Oracle PeopleSoft zero-day, reportedly using it to gain remote code execution through infrastructure connected to the FBI’s recruitment services. The attackers also reportedly claimed access to several FBI-related services, including human resources systems and a system they referred to as Medlink. They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised. There is also a clear motive behind the operation claimed by ShinyHunters. The group says it targeted the FBI after a May 2026 public advisory describing its tactics and warning victims against paying. ShinyHunters disputes the FBI’s characterization of its activities and is reportedly demanding that the Bureau retract or correct the warning. This makes the alleged attack unusual. Instead of immediately demanding a conventional ransom, the group appears to be using the stolen data as leverage in a dispute with U.S. law enforcement. The timing is also significant. ShinyHunters has recently claimed responsibility for several major breaches and has been involved in a public dispute with the Clop cybercrime operation. The group recently claimed to have compromised Clop’s data leak site, highlighting the increasingly aggressive behavior surrounding the group. The stolen data is much more sensitive than the usual names and email addresses seen in data breaches. It includes details about named employees’ counterintelligence roles, home addresses of human intelligence operatives, and medical and psychiatric records of FBI staff. For an agency where some employees depend on keeping their identities, jobs and home addresses private, this goes beyond a normal data breach. It creates a serious operational security risk. Last week a key ShinyHunters suspect got picked up in Jordan and reportedly started cooperating with investigators, which might help the bureau understand just how bad the damage really is. Removing one contractor doesn’t undo an exposure like this, it just closes the door after the fact. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Accenture)
[messages.read_original_source] →