HackRead

FBI Removes Accenture Contractor Over ShinyHunters Job Site Data Breach


The US Federal Bureau of Investigation (FBI) has removed a contractor after a breach exposed sensitive information belonging to thousands of bureau employees. Two sources familiar with the case told Reuters that the contractor worked for Accenture.

Brett Leatherman, assistant director of the FBI’s Cyber Division, said the incident resulted from a security failure involving a platform managed by a third-party organization.

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman told Reuters.

He added that the FBI had removed the contractor and taken steps to limit further risk and protect its workforce.

The FBI did not identify the contractor, the affected platform or the company responsible for managing it. Reuters sources identified the software as Oracle PeopleSoft, a human resources platform, and the third-party provider as Accenture. The news agency could not determine the contractor’s identity or current employment status.

Accenture said it was “proud to support the mission of the FBI and will continue to do so,” but did not answer questions about the contractor or the missed security update.

ShinyHunters Claims PeopleSoft Flaw Enabled Access

ShinyHunters previously claimed it used a PeopleSoft vulnerability to access the FBI’s job portal. Mandiant has separately documented the group’s exploitation of CVE-2026-35273, a critical vulnerability in the PeopleSoft Environment Management component, but it has not publicly connected its observations to the FBI breach.

According to Mandiant, ShinyHunters used URL encoding to bypass web application firewall (WAF) rules that blocked access to the vulnerable /PSEMHUB/ endpoint.

The group sent requests to /%50SEMHUB/, replacing the letter “P” with its encoded value. A WAF checking for the literal /PSEMHUB/ path could treat the encoded request as different, while PeopleSoft decoded it and passed the request to the vulnerable application.

Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions. Oracle issued an out-of-band security alert on June 10.

Later attacks targeted organizations in technology, IT services, healthcare, agriculture, transportation and government. Mandiant found web shells on dozens of PeopleSoft systems worldwide, including servers whose operators had deployed WAF rules without installing Oracle’s security update.

According to Reuters, information exposed in the FBI breach included medical and psychiatric records, street addresses belonging to human intelligence operatives and detailed descriptions of named employees’ counterintelligence roles.

FBI Investigation Continues

The development follows Hackread.com’s September 22 report on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.

The group claimed it had accessed information belonging to current and former FBI employees, as well as job applicants. The compromised portal displayed a page stating that the site had been seized, accompanied by claims involving personally identifiable information (PII) and protected health information (PHI).

ShinyHunters later described the attack as retaliation for an FBI advisory about the group’s activities and demanded that the bureau change or retract its comments.

Reuters reported on October 3 that suspected ShinyHunters member Saif al-Din Khader was detained in Jordan and was cooperating with the FBI and other authorities. The bureau has not publicly confirmed Khader’s detention.





Source link