FBI Blames Accenture Contractor for ShinyHunters Breach of Employee Data

3 min read
Source: The Hacker News
FBI Blames Accenture Contractor for ShinyHunters Breach of Employee Data
Photo: The Hacker News
TL;DR

The FBI has removed an Accenture contractor after a failure to apply a security patch allowed the ShinyHunters hacking group to breach the bureau's job portal. The incident exposed sensitive personal data of nearly all FBI employees and over 8,000 local law enforcement officials. While the FBI attributes the breach to a third-party platform failure, internal sources describe it as an act of incompetence involving misconfigured internet-facing systems.

Key points

  • The FBI removed an Accenture contractor for failing to implement a security patch on a platform managed by a third party, according to Assistant Director Brett Leatherman.
  • The breach exploited a vulnerability in Oracle PeopleSoft, specifically a bypass for CVE-2026-35273, to access the FBI's job portal.
  • Stolen data includes names, addresses, phone numbers, and Social Security numbers of nearly every FBI employee and over 8,000 state and local law enforcement officers.
  • Two ShinyHunters members have been arrested, with the FBI warning that more arrests are likely as the investigation continues.
  • The hackers did not access core investigative networks or classified systems, but experts warn the data poses a long-term national security threat.

Background

In late September 2026, the hacking group ShinyHunters claimed to have breached the FBI, stealing two to three terabytes of data via a zero-day exploit in Oracle PeopleSoft. The group stated the breach was a retaliatory response to a May 2026 FBI advisory warning targets not to pay ransoms. At that time, the FBI confirmed an investigation but declined to verify the extent of the data theft, while Reuters partially verified nine records from a sample provided by the hackers.

How outlets are covering it

The FBI and Reuters emphasize the breach as a result of a third-party security failure, specifically an Accenture contractor's failure to patch Oracle PeopleSoft. In contrast, MS NOW reports that internal FBI officials and cybersecurity experts describe the incident as an act of 'incompetence,' noting that sensitive data was improperly moved to an internet-facing system despite a June warning from Google's threat intelligence experts. While the FBI focuses on the contractor's removal, MS NOW highlights the negligence in data management and the potential for foreign adversaries to exploit the stolen information.

Why it matters

The breach exposes the personal and professional details of nearly all FBI employees and thousands of local law enforcement officials, creating significant risks for counterintelligence and national security. The incident highlights vulnerabilities in third-party vendor management and the potential for high-profile breaches to have long-term implications for government security operations.

What to watch

The FBI is actively working with partners to obtain and execute more leads, with officials warning that additional arrests are likely. The agency has taken steps to mitigate further risk and protect its workforce, while the ShinyHunters group has stated it does not plan to release the full data set.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News