FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees
FBI removed an Accenture contractor after an unpatched Oracle PeopleSoft HR system exposed thousands of employees' sensitive personal data.
The FBI removed an Accenture contractor on October 5, 2026 after a missed patch led to a breach exposing sensitive personal details of thousands of employees; FBI cyber chief Brett Leatherman confirmed a contractor failed to install a patch on a third-party-managed platform. Reuters identified Oracle's PeopleSoft HR platform as the affected system and Accenture as the service provider. The incident follows ShinyHunters' September claim of breaching the FBI job website via a PeopleSoft flaw, with exposed data reportedly including names of staff in sensitive units and medical and psychiatric records. The FBI statement does not name a CVE, but prior reporting covered CVE-2026-35273, a critical PeopleSoft flaw allowing unauthenticated code execution via the Environment Management Hub, and Mandiant reported renewed PeopleSoft attacks against organizations relying on WAF rules instead of patches.
- FBI removed Accenture contractor over missed patch exposing thousands of employees' data
- Oracle PeopleSoft HR platform identified as the breached system
- Follows ShinyHunters' September claim of breaching FBI jobs site
- Exposed data reportedly included sensitive-unit staff names and medical records
- Mandiant reported attackers bypassing WAF rules on unpatched PeopleSoft systems
Vulnerabilities mentionedAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article422 words · extracted from cybersecuritynews.com · click to collapse
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch led to a data breach exposing sensitive personal details of thousands of employees. According to Reuters, two sources identified Oracle’s PeopleSoft human resources platform as the affected system and Accenture as the service provider.
FBI cyber chief Brett Leatherman said the bureau’s review found that a contractor failed to install a patch issued to secure a platform managed by a third party. He said the FBI had removed the contractor and taken steps to reduce further risk and protect its workforce.
The FBI did not publicly name PeopleSoft or Accenture in its statement. Reuters could not establish the contractor’s identity or current employment status. Accenture said it would continue supporting the FBI but did not answer questions about the contractor or the alleged patching failure.
FBI Removes Accenture Contractor
The incident follows ShinyHunters’ claim that it breached the FBI’s job website through a PeopleSoft flaw in September. Earlier reporting described exposed names of staff in sensitive units and medical and psychiatric records. Such disclosures raise concerns beyond identity theft because they reveal information about employees working in sensitive roles.
However, Reuters previously said it could not confirm the group’s claimed PeopleSoft entry route. The contractor’s removal confirms a patching failure identified by the FBI, not every technical detail offered by the hackers about how they gained access.
Separate research provides important context. Cyber Security News previously covered CVE-2026-35273, a critical PeopleSoft flaw that allows attackers to run code without signing in. That report identified the Environment Management Hub component as the target. The available FBI statement does not identify a CVE or confirm that the specific vulnerability was exploited.
In September, Google’s Mandiant reported renewed PeopleSoft attacks against organizations that used web application firewall rules but had not installed Oracle’s update. Attackers adapted to those defenses, showing why temporary filters cannot replace a patch that fixes the underlying flaw.
For PeopleSoft administrators, the practical lesson is to apply vendor fixes promptly, verify installation, and check for suspicious access. Clear patching duties also matter when outside contractors manage sensitive employee systems.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.