The FBI has terminated its relationship with a contractor following a data breach that compromised personal information of numerous bureau employees. This decision, reported by Reuters, stems from the contractor’s failure to implement a crucial security patch.
Contractor’s Security Oversight
Although the FBI has not disclosed the contractor’s identity, a senior official indicated that the breach resulted from a security lapse involving a third-party managed platform. FBI Cyber Chief Brett Leatherman confirmed that the incident was due to a missed security patch meant to safeguard the system.
Leatherman stated, “Our assessment shows the breach occurred because a contractor did not apply a security patch designed to protect the platform.” Consequently, the FBI has removed the contractor and taken steps to mitigate future risks and protect its workforce.
Involvement of Accenture and Oracle’s PeopleSoft
Sources from Reuters identified the system as Oracle’s PeopleSoft human resources platform, managed by Accenture. The ShinyHunters group reportedly exploited vulnerabilities in PeopleSoft to infiltrate the FBI’s job site, with Google warning about ongoing threats to similar systems.
Accenture responded by expressing its commitment to supporting the FBI but did not comment on the contractor or the patch failure allegations.
ShinyHunters’ Cyber Attack
ShinyHunters announced on September 22 that they had breached FBI systems, targeting the bureau’s jobs website. The group claimed to have accessed sensitive employee information, some of which was leaked to the media. They allegedly aimed to pressure the FBI to retract a previous report about ShinyHunters’ activities.
Despite the arrest of a purported leader in the Netherlands on September 15, the group continued to demand negotiations from victims, threatening further data leaks. The arrest of another leader, Saif al-Din Khader, known as Rey, in Jordan was reported on October 3, although ShinyHunters’ site remains active with recent posts.
This incident highlights the ongoing challenges and threats in cybersecurity, underscoring the importance of timely security updates and vigilant oversight of third-party contractors.
