FBI removes Accenture contractor after missed security patch led to breach

<p>The FBI has severed ties with a contractor working for Accenture amid a massive cybercrime intrusion that may have exposed data on thousands of bureau employees, according to a person with knowledge of the matter.</p>

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

<p>Prolific cybercrime group ShinyHunters claimed responsibility for the hack last month. The data stolen contained employees&rsquo; addresses, phone numbers and information on their spouses, among other categories. It also revealed sensitive data on employees&rsquo; <a href=“Stolen FBI data reveals employees’ roles in intelligence and surveillance - Nextgov/FCW”>intelligence and surveillance roles</a>, as well as private medical information.</p>

<p>Accenture is responsible for software patch management and maintaining custom code at the FBI, said the person, who spoke on the condition of anonymity because the situation is sensitive. Oracle &mdash; whose PeopleSoft platform was the initial access point that ShinyHunters claimed to have exploited &mdash; provided the security patches that were not integrated, the person added.</p>

<p>FBI cybersecurity chief Brett Leatherman confirmed the removal of an unnamed contractor in a statement to <em>Nextgov/FCW</em>.</p>

<p>&ldquo;To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization &mdash; after a contractor failed to implement a security patch explicitly issued to secure the platform,&rdquo; Leatherman said. &ldquo;As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.&rdquo;</p>

<p>The remarks offer the bureau&rsquo;s clearest explanation yet of how the intrusion occurred, though they do not address why the patch was missed and how the FBI monitored the contractor&rsquo;s work to ensure systems holding sensitive employee information were protected.</p>

<p><a href=“https://www.reuters.com/technology/accenture-contractor-removed-fbi-following-damaging-data-breach-sources-say-2026-10-06/”>Reuters first reported</a> the removal late Monday. The specific Accenture employee could not be immediately identified.</p>

<p>In a statement, the company said it&rsquo;s &ldquo;proud to support the mission of the FBI and will continue to do so.&rdquo;</p>

<p>The breach follows recent<a href=“https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft”> findings from Google&rsquo;s Mandiant</a> that ShinyHunters had resumed widespread exploitation of a PeopleSoft vulnerability for which Oracle issued a patch in June.&nbsp;</p>

<p>The incident poses serious counterintelligence risks because the exposed records could help foreign intelligence services identify employees working on sensitive investigations and exploit personal information about them.&nbsp;</p>

<p>ShinyHunters has<a href=“ShinyHunters says it won’t publish FBI data - Nextgov/FCW”> said it would not publish the stolen data</a>, but its statement did not say the records had been deleted. Retired Lt. Gen. Robert Skinner, who previously led the Defense Information Systems Agency,<a href=“FBI warns ShinyHunters members to come forward after alleged leader’s arrest - Nextgov/FCW”> told <em>Nextgov/FCW</em> last week</a> that the group could still sell some or all of the information to foreign intelligence services or other buyers.</p>

<p>Authorities have also moved against suspected members of the group. Dutch police last week announced the arrest of an alleged leader, and<a href=“https://www.reuters.com/world/middle-east/key-shinyhunters-hacker-detained-jordan-is-cooperating-sources-say-2026-10-03/”> Reuters reported Saturday</a> that another suspected member, Saif al-Din Khader, had been detained in Jordan and was helping investigators locate other hackers.</p>

Article Link: FBI removes Accenture contractor after missed security patch led to breach - Nextgov/FCW