FBI removes Accenture contractor after PeopleSoft data breach
The FBI removed an Accenture contractor after unpatched Oracle PeopleSoft exposed thousands of employees’ data that ShinyHunters claimed to steal.
On October 5, 2026, the FBI removed an Accenture contractor after a missed security patch on a third-party platform exposed personal data of thousands of bureau employees, Cyber Division Assistant Director Brett Leatherman told Reuters. Reuters sources identified Oracle PeopleSoft, used for the FBI jobs site and managed by Accenture, although the bureau has not officially named the company, has not confirmed that internal systems were compromised, and says it is still assessing impact while stating that risk is mitigated. ShinyHunters claimed a September intrusion—September 22 in one account—and theft ranging in reports from data on all employees to roughly 2 to 3 terabytes and a sample of about 5,000 records that Reuters partially matched, including records linked to Director Kash Patel; some outlets also reported medical or psychiatric records and sensitive operational details. Early CSO reporting said the group claims a second undocumented pre-authentication remote-code-execution flaw distinct from CVE-2026-35273, but no CVE, CISA KEV entry, or Oracle confirmation supports that claim, while later reports point to a missed patch and Oracle’s June advisory for CVE-2026-35273, a CVSS 9.8 unauthenticated flaw in PeopleTools 8.61 and 8.62 affecting the Environment Management Hub, which the FBI has not confirmed as the entry point. Mandiant said URL encoding bypassed a firewall rule for that flaw, and analysts urged patching, removing the Environment Management Hub and Integration Broker from the internet, and hunting for web shells. Arrest reporting conflicts: the FBI said two members were arrested and more arrests are likely, while other reports cite the Netherlands on September 15 and Jordan around October 3, with one suspect said to be cooperating.
- On October 5, 2026, the FBI removed an Accenture contractor after a missed security patch; Cyber Division Assistant Director Brett Leatherman said a contractor left a third-party platform unpatched. Reuters sources named Oracle PeopleSoft…
- The breach exposed personal data of thousands of FBI employees. ShinyHunters claimed a September intrusion, dated September 22 in one report, and theft of roughly 2 to 3 terabytes plus a sample of about 5,000 records that Reuters partly…
- Reported contents, not uniformly confirmed, include names, Social Security numbers, addresses, phone numbers, assignments, sensitive-unit names, counterintelligence duties, human-intelligence operative addresses, and medical or psychiatric…
- Oracle’s June advisory describes CVE-2026-35273 as a CVSS 9.8 unauthenticated remote-code-execution flaw in PeopleTools 8.61 and 8.62 via the Environment Management Hub. The FBI has not confirmed that CVE was used. CSO reported an…
- Mandiant said URL-encoded requests bypassed a web-application firewall rule for CVE-2026-35273. Analysts urged patching, taking the Environment Management Hub and Integration Broker off the internet, and hunting for web shells.
- Arrest accounts differ: the FBI said two ShinyHunters members were arrested and more arrests are likely; other reports place alleged leaders in the Netherlands on September 15 and in Jordan around October 3, with cooperation attributed…
Coverage timelineoldest first · each row is one article
- · 2d agoShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics
CSO Online· 80
ShinyHunters claims a new PeopleSoft pre-auth RCE zero-day used to breach the FBI, which confirmed the intrusion.
- · 2d agoDespite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks
CSO Online· 80
PeopleSoft customers lack vendor guidance as ShinyHunters claims a second zero-day after the confirmed FBI breach.
- · 2d ago
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|