FBI Blames Accenture Contractor for ShinyHunters Breach of Employee Data

The FBI has removed an Accenture contractor after a failure to apply a security patch allowed the ShinyHunters hacking group to breach the bureau's job portal. The incident exposed sensitive personal data of nearly all FBI employees and over 8,000 local law enforcement officials. While the FBI attributes the breach to a third-party platform failure, internal sources describe it as an act of incompetence involving misconfigured internet-facing systems.
Key points
- The FBI removed an Accenture contractor for failing to implement a security patch on a platform managed by a third party, according to Assistant Director Brett Leatherman.
- The breach exploited a vulnerability in Oracle PeopleSoft, specifically a bypass for CVE-2026-35273, to access the FBI's job portal.
- Stolen data includes names, addresses, phone numbers, and Social Security numbers of nearly every FBI employee and over 8,000 state and local law enforcement officers.
- Two ShinyHunters members have been arrested, with the FBI warning that more arrests are likely as the investigation continues.
- The hackers did not access core investigative networks or classified systems, but experts warn the data poses a long-term national security threat.
Background
In late September 2026, the hacking group ShinyHunters claimed to have breached the FBI, stealing two to three terabytes of data via a zero-day exploit in Oracle PeopleSoft. The group stated the breach was a retaliatory response to a May 2026 FBI advisory warning targets not to pay ransoms. At that time, the FBI confirmed an investigation but declined to verify the extent of the data theft, while Reuters partially verified nine records from a sample provided by the hackers.
How outlets are covering it
The FBI and Reuters emphasize the breach as a result of a third-party security failure, specifically an Accenture contractor's failure to patch Oracle PeopleSoft. In contrast, MS NOW reports that internal FBI officials and cybersecurity experts describe the incident as an act of 'incompetence,' noting that sensitive data was improperly moved to an internet-facing system despite a June warning from Google's threat intelligence experts. While the FBI focuses on the contractor's removal, MS NOW highlights the negligence in data management and the potential for foreign adversaries to exploit the stolen information.
Why it matters
The breach exposes the personal and professional details of nearly all FBI employees and thousands of local law enforcement officials, creating significant risks for counterintelligence and national security. The incident highlights vulnerabilities in third-party vendor management and the potential for high-profile breaches to have long-term implications for government security operations.
What to watch
The FBI is actively working with partners to obtain and execute more leads, with officials warning that additional arrests are likely. The agency has taken steps to mitigate further risk and protect its workforce, while the ShinyHunters group has stated it does not plan to release the full data set.
- FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach The Hacker News
- EXCLUSIVE: Accenture contractor removed from FBI following damaging data breach, sources say Reuters
- Our Reporter Emailed the F.B.I. Hackers. They Wrote Back. The New York Times
- FBI confirms 'multiple' arrests related to ShinyHunters hack The Register
- ‘Incompetence’: Massive FBI hack hit most employees and extends to local officials MS NOW
Want the full story? Read the original reporting
Read on The Hacker News