NEWS

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The FBI fired an Accenture contractor who skipped a required patch, letting ShinyHunters breach its jobs portal via an Oracle PeopleSoft flaw.

Dylan H.

News Desk

October 6, 2026
5 min read
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

A Patch That Never Got Applied

The FBI has removed an Accenture contractor after determining the contractor failed to implement a security patch that had been explicitly issued to secure the bureau's Oracle PeopleSoft platform — an oversight that opened the door for the ShinyHunters extortion group to breach the FBI's jobs portal and steal personal data on thousands of agency employees. The disclosure, first reported by Reuters citing two sources familiar with the matter, adds a concrete root cause to a breach the bureau had been investigating since late September.


Details

AttributeValue
Vulnerability ExploitedCVE-2026-35273 (Oracle PeopleSoft)
Bypass TechniqueURL-encoding to slip malicious requests past the WAF
TargetFBI jobs/applicant portal, built on PeopleSoft
Root CauseContractor failed to apply a patch explicitly issued for the platform
Responsible PartyThird-party Accenture contractor
FBI ResponseContractor removed; mitigation steps taken
AttributionShinyHunters (analysis via Google Mandiant)
Reported ByReuters, citing sources familiar with the matter

From Defacement Claim to Confirmed Root Cause

ShinyHunters first drew FBI attention in late September when it defaced the bureau's jobs site and claimed to hold data on nearly all FBI agents and applicants — a claim the FBI said at the time it was investigating. Days later, Google's threat intelligence arm, Mandiant, published analysis showing ShinyHunters was mass-exploiting CVE-2026-35273, a previously patched PeopleSoft remote-code-execution flaw, by URL-encoding requests to the vulnerable Environment Management Hub endpoint so they would slip past web application firewalls designed to block it. Reuters' sourcing now ties that same exploitation path directly to the FBI's own portal: the patch meant to close CVE-2026-35273 was never applied to the system an Accenture contractor was responsible for maintaining.

The FBI's Statement

Brett Leatherman, the FBI's assistant director of the cyber division, said the incident "occurred as the result of a security failure ... after a contractor failed to implement a security patch explicitly issued to secure the platform." Leatherman added that the bureau has "removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." The statement is notable for assigning the failure squarely to a specific, named class of actor — a third-party contractor — rather than describing the breach only in terms of the attacker's technique.

What Was Taken

The breach exposed personal information belonging to thousands of FBI employees who had used the jobs/applicant portal. The bureau has not published a precise record count, and the investigation into the full scope of exposed data remains active.

Investigation and Enforcement Status

The broader ShinyHunters case against the FBI has already produced arrests: two alleged members of the group have been detained, including a suspect reportedly held in Jordan while assisting law enforcement in identifying other members of the collective. The FBI says it continues to pursue additional leads and anticipates further arrests.


Why This Matters

  • Third-party risk is first-party risk. The vulnerability (CVE-2026-35273) had already been patched by Oracle and was circulating in public advisories; the failure here was entirely downstream, in a contractor's patch-management discipline on a system it was paid to maintain.
  • WAF rules are not a substitute for patching. ShinyHunters' URL-encoding bypass worked specifically because the underlying flaw remained unpatched — the WAF was the only line of defense, and it was evaded with a well-known encoding trick.
  • Accountability language is shifting. By naming the failure mode publicly — a contractor skipping a mandated patch — the FBI is setting a precedent that agencies may increasingly hold specific named failures, not just "sophisticated attackers," responsible for breaches.

Recommendations

For Organizations Using Third-Party Contractors

  • Maintain an independent, agency-owned patch-compliance ledger for any system a contractor manages — don't rely solely on contractor self-attestation.
  • Require contractors to confirm patch application against a specific CVE ID and timestamp, not just "system updated."
  • Periodically audit contractor-managed systems against the vendor's own advisory list, especially for internet-facing platforms like PeopleSoft.

For PeopleSoft Administrators

  • Confirm CVE-2026-35273 is patched on every PeopleSoft instance, including Environment Management Hub endpoints — WAF rules alone do not close this gap.
  • Review WAF logs for URL-encoded request patterns targeting PeopleSoft management endpoints, a known ShinyHunters bypass technique.
  • Treat any PeopleSoft deployment maintained by a third party as high-priority for an independent verification pass.

Key Takeaways

  1. The FBI jobs-portal breach traces to a specific, named root cause: an Accenture contractor's failure to apply a patch for CVE-2026-35273.
  2. ShinyHunters used a URL-encoding bypass to exploit the unpatched Oracle PeopleSoft Environment Management Hub endpoint, evading WAF protections.
  3. The FBI has removed the contractor and taken additional mitigation steps; the investigation into the full scope of exposed data continues.
  4. Two alleged ShinyHunters members have already been detained in connection with the broader campaign against the FBI.

Sources