A Patch That Never Got Applied
The FBI has removed an Accenture contractor after determining the contractor failed to implement a security patch that had been explicitly issued to secure the bureau's Oracle PeopleSoft platform — an oversight that opened the door for the ShinyHunters extortion group to breach the FBI's jobs portal and steal personal data on thousands of agency employees. The disclosure, first reported by Reuters citing two sources familiar with the matter, adds a concrete root cause to a breach the bureau had been investigating since late September.
Details
| Attribute | Value |
|---|---|
| Vulnerability Exploited | CVE-2026-35273 (Oracle PeopleSoft) |
| Bypass Technique | URL-encoding to slip malicious requests past the WAF |
| Target | FBI jobs/applicant portal, built on PeopleSoft |
| Root Cause | Contractor failed to apply a patch explicitly issued for the platform |
| Responsible Party | Third-party Accenture contractor |
| FBI Response | Contractor removed; mitigation steps taken |
| Attribution | ShinyHunters (analysis via Google Mandiant) |
| Reported By | Reuters, citing sources familiar with the matter |
From Defacement Claim to Confirmed Root Cause
ShinyHunters first drew FBI attention in late September when it defaced the bureau's jobs site and claimed to hold data on nearly all FBI agents and applicants — a claim the FBI said at the time it was investigating. Days later, Google's threat intelligence arm, Mandiant, published analysis showing ShinyHunters was mass-exploiting CVE-2026-35273, a previously patched PeopleSoft remote-code-execution flaw, by URL-encoding requests to the vulnerable Environment Management Hub endpoint so they would slip past web application firewalls designed to block it. Reuters' sourcing now ties that same exploitation path directly to the FBI's own portal: the patch meant to close CVE-2026-35273 was never applied to the system an Accenture contractor was responsible for maintaining.
The FBI's Statement
Brett Leatherman, the FBI's assistant director of the cyber division, said the incident "occurred as the result of a security failure ... after a contractor failed to implement a security patch explicitly issued to secure the platform." Leatherman added that the bureau has "removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." The statement is notable for assigning the failure squarely to a specific, named class of actor — a third-party contractor — rather than describing the breach only in terms of the attacker's technique.
What Was Taken
The breach exposed personal information belonging to thousands of FBI employees who had used the jobs/applicant portal. The bureau has not published a precise record count, and the investigation into the full scope of exposed data remains active.
Investigation and Enforcement Status
The broader ShinyHunters case against the FBI has already produced arrests: two alleged members of the group have been detained, including a suspect reportedly held in Jordan while assisting law enforcement in identifying other members of the collective. The FBI says it continues to pursue additional leads and anticipates further arrests.
Why This Matters
- Third-party risk is first-party risk. The vulnerability (CVE-2026-35273) had already been patched by Oracle and was circulating in public advisories; the failure here was entirely downstream, in a contractor's patch-management discipline on a system it was paid to maintain.
- WAF rules are not a substitute for patching. ShinyHunters' URL-encoding bypass worked specifically because the underlying flaw remained unpatched — the WAF was the only line of defense, and it was evaded with a well-known encoding trick.
- Accountability language is shifting. By naming the failure mode publicly — a contractor skipping a mandated patch — the FBI is setting a precedent that agencies may increasingly hold specific named failures, not just "sophisticated attackers," responsible for breaches.
Recommendations
For Organizations Using Third-Party Contractors
- Maintain an independent, agency-owned patch-compliance ledger for any system a contractor manages — don't rely solely on contractor self-attestation.
- Require contractors to confirm patch application against a specific CVE ID and timestamp, not just "system updated."
- Periodically audit contractor-managed systems against the vendor's own advisory list, especially for internet-facing platforms like PeopleSoft.
For PeopleSoft Administrators
- Confirm CVE-2026-35273 is patched on every PeopleSoft instance, including Environment Management Hub endpoints — WAF rules alone do not close this gap.
- Review WAF logs for URL-encoded request patterns targeting PeopleSoft management endpoints, a known ShinyHunters bypass technique.
- Treat any PeopleSoft deployment maintained by a third party as high-priority for an independent verification pass.
Key Takeaways
- The FBI jobs-portal breach traces to a specific, named root cause: an Accenture contractor's failure to apply a patch for CVE-2026-35273.
- ShinyHunters used a URL-encoding bypass to exploit the unpatched Oracle PeopleSoft Environment Management Hub endpoint, evading WAF protections.
- The FBI has removed the contractor and taken additional mitigation steps; the investigation into the full scope of exposed data continues.
- Two alleged ShinyHunters members have already been detained in connection with the broader campaign against the FBI.
Related Reading
- FBI Investigating Alleged ShinyHunters Breach of Its Jobs Site
- ShinyHunters Bypass WAFs to Exploit Oracle PeopleSoft Flaw at Scale
- ShinyHunters Suspect "Rey" Reportedly Detained in Jordan, Helping FBI Identify Group