FBI Blames Accenture Contractor for ShinyHunters Breach of Jobs Portal

3 min read
Source: NBC News
FBI Blames Accenture Contractor for ShinyHunters Breach of Jobs Portal
Photo: NBC News
TL;DR

The FBI attributes the recent breach of its jobs website to a contractor’s failure to install a critical security patch. Cyber-extortion group ShinyHunters claimed responsibility, alleging it stole 2-3 terabytes of data, including details on all FBI employees. The agency has removed the contractor, identified as working for Accenture, and arrested multiple suspects, including a leader detained in Jordan.

Key points

  • FBI Cyber Division Assistant Director Brett Leatherman stated the breach resulted from a third-party contractor failing to implement a security patch for the platform.
  • ShinyHunters claimed to have exploited a vulnerability in Oracle PeopleSoft to access AWS GovCloud servers and steal data on nearly all FBI employees and 8,000 local law enforcement officials.
  • The FBI has removed the contractor, identified by PCMag and Reuters as an Accenture employee, and confirmed multiple arrests in connection with the incident.
  • A suspected ShinyHunters leader, Saif al-Din Khader, was detained in Jordan and is reportedly cooperating with investigators.
  • The vulnerability, CVE-2026-35273, was publicly patched in June, three months before the breach, raising questions about the contractor's negligence.

Background

The FBI jobs portal was defaced and taken offline in late September after ShinyHunters claimed the breach. The group, which previously targeted companies like Rockstar Games, demanded the removal of a May 2026 FBI advisory labeling them a cyber-criminal group rather than demanding ransom. The incident exposed sensitive personal data, including names, addresses, and spouse information, of FBI employees and applicants.

How outlets are covering it

NBC News and PCMag report that the FBI has removed the contractor, with PCMag and Reuters identifying the firm as Accenture. CBS News highlights the detention of Saif al-Din Khader in Jordan, noting he is cooperating with investigators. While the FBI attributes the breach to a contractor's failure, internal sources described it as an act of incompetence involving misconfigured systems. ShinyHunters claims to have stolen 2-3 terabytes of data, but NBC News notes it could not verify the extent of the claims. The FBI has confirmed multiple arrests, including a 24-year-old from Amsterdam, Pepijn van der Stap, who was arrested in September before the group publicly claimed the hack.

Why it matters

The breach highlights the risks of third-party contractor failures in securing critical government infrastructure. The incident exposed sensitive data of FBI employees and local law enforcement officials, potentially compromising undercover operatives. The FBI's response, including the removal of the contractor and multiple arrests, signals a focus on holding responsible parties accountable for cybersecurity failures.

What to watch

The FBI is continuing its investigation into the ShinyHunters group, with multiple arrests already occurring. The agency is working with partners to obtain and execute more leads based on the arrests. The FBI has also taken steps to mitigate further risk and protect its workforce. The contractor has been removed, and the agency is focusing on securing its platforms.

Share this article

Want the full story? Read the original reporting

Read on NBC News