The Federal Bureau of Investigation (FBI) has terminated an Accenture contractor for their alleged involvement in a significant security breach linked to the ShinyHunters hacking group. This incident resulted in the unauthorized access to personal information of numerous FBI employees.
According to a report by Reuters, which cited two individuals familiar with the situation, the breach was attributed to a failure in implementing a crucial security update on a third-party managed platform.
Security Patch Oversight Leads to Breach
Brett Leatherman, assistant director of the FBI’s cyber division, highlighted that the security lapse was due to a contractor’s failure to apply a necessary security patch. This oversight compromised the platform’s integrity, leading to the breach.
The FBI has since removed the contractor and is actively taking measures to mitigate any further risks and ensure the protection of its personnel. Although the FBI has not named the third-party organization involved, sources suggest Oracle PeopleSoft was implicated in the breach.
Exploiting Vulnerabilities for Access
ShinyHunters, a notorious hacking group, reportedly exploited a vulnerability, identified as CVE-2026-35273, by bypassing a web application firewall using a URL-encoding technique. This allowed them to access the FBI’s job portal last month without detection.
Google-owned Mandiant provided insights into the methods employed by ShinyHunters, emphasizing the need for robust security measures in combating such sophisticated cyber threats.
Ongoing Investigations and Future Implications
The breach marks another chapter in ShinyHunters’ operational history, with two members previously apprehended. The FBI continues its investigation, collaborating with partners to gather more intelligence and execute further arrests.
In light of these developments, Accenture expressed its commitment to supporting the FBI’s mission and maintaining strong cybersecurity defenses. As the investigation progresses, the agency remains vigilant in its efforts to prevent future breaches.
Both the FBI and Oracle have been contacted for comments, and updates will be provided as more information becomes available.
