Accenture Contractor Removed After FBI Data Breach Exposes Thousands of Employees
FBI removed an Accenture contractor after a PeopleSoft breach exposed thousands of employees' sensitive data.
On October 5, the FBI removed an Accenture contractor after a breach of an HR platform exposed sensitive data on thousands of employees, Reuters reported. Sources identified Oracle PeopleSoft as the system; ShinyHunters claimed it exploited PeopleSoft against the FBI job site in September. Oracle's June advisory describes CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in PeopleTools 8.61 and 8.62, but the FBI has not confirmed that CVE was used. Reported leaks included counterintelligence duties, addresses of human-intelligence operatives, and medical and psychiatric records. A ShinyHunters suspect detained in Jordan is cooperating.
- FBI ended an Accenture contract after an unpatched HR platform was breached.
- Sources name Oracle PeopleSoft; ShinyHunters claimed the September intrusion.
- CVE-2026-35273 scores 9.8 and allows unauthenticated remote code execution.
- Exposed data reportedly included operative addresses and psychiatric records.
- FBI has not confirmed CVE-2026-35273 was the entry point.
Vulnerabilities mentionedAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article494 words · extracted from gbhackers.com · click to collapse
On October 5, the Federal Bureau of Investigation (FBI) terminated an Accenture employee’s contract after a security breach exposed sensitive information belonging to thousands of workers, according to Reuters.
The incident involved an allegedly unpatched human resources platform, raising concerns about the bureau’s operational security.
FBI cyber chief Brett Leatherman confirmed that the contractor failed to implement a security patch specifically issued to protect a platform managed by a third-party organization.
He said the bureau removed the contractor and took steps to mitigate further risk and protect its workforce.
Accenture Contractor Removed After FBI Data Breach
While the FBI did not publicly identify the affected platform or service provider, two sources familiar with the investigation have identified Oracle PeopleSoft as the breached system and Accenture as its manager.
The hacking group ShinyHunters previously claimed responsibility for exploiting PeopleSoft to access the FBI’s job site in September.
Reuters could not identify the specific contractor involved or confirm their current employment status. Therefore, the contractor’s removal should not be interpreted as confirmation that Accenture terminated their employment.
Accenture stated that it remains committed to supporting the FBI but did not respond to questions about the alleged failure to implement the necessary security patch. Oracle also did not provide immediate comments.
Oracle’s security advisory from June 10 describes CVE-2026-35273, a critical vulnerability affecting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. This flaw, located in the Updates Environment Management component, carries a CVSS 3.1 severity score of 9.8.
According to Oracle, attackers can exploit the vulnerability remotely over HTTP without needing authentication or user interaction.
Successful exploitation may lead to remote code execution, posing significant risks to confidentiality, integrity, and availability. Oracle has urged its customers to implement recommended mitigations and apply security updates immediately.
Although this advisory provides important technical details, the FBI has not publicly confirmed whether this specific CVE was the entry point for the breach.
Reuters could not determine whether and when those responsible for securing the bureau’s job site implemented the recommended protections. ShinyHunters attributed its intrusion to a vulnerability in PeopleSoft.
The leaked information reportedly included detailed descriptions of employees’ counterintelligence responsibilities, street addresses of human intelligence operatives, and medical and psychiatric records of bureau personnel.
Former officials described the breach as a significant blow to operational security, while the FBI continues to assess its consequences.
These disclosures extend beyond typical employee data exposure; the compromised information reportedly links identifiable personnel with sensitive intelligence roles and deeply private health information. Investigators are still determining the full extent of the damage.
Additionally, Reuters reported that a key suspect from ShinyHunters, who was detained in Jordan, is cooperating with investigators. This cooperation could help authorities understand the breach and potentially mitigate its impact on affected personnel.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.