The FBI removed a contractor after an internal review linked a breach exposing sensitive personal information about thousands of employees to a missed security patch on a third-party-managed platform. FBI cyber division assistant director Brett Leatherman said the contractor failed to implement an explicitly issued patch. Sources cited by Reuters identified Accenture as the service provider and Oracle PeopleSoft as the affected platform, although the FBI did not publicly name either company. Earlier reporting described exposed employee names from sensitive units, along with medical and psychiatric records.
ShinyHunters claimed it breached the FBI’s job website through a PeopleSoft vulnerability, but Reuters could not confirm that entry route, and the FBI did not identify an exploited CVE. Separately, Mandiant assessed that ShinyHunters was using URL encoding to bypass a web application firewall rule blocking the vulnerable PSEMHUB endpoint associated with CVE-2026-35273; that observation provides context, not confirmation of the FBI breach mechanism. Two ShinyHunters members have been arrested, and the FBI said its continuing investigation could lead to further arrests. The incident underscores the need to verify third-party patch deployment rather than rely solely on contractor assurances or WAF protections.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
The FBI removed a contractor after its review attributed the breach to failure to install an explicitly issued security patch, and took steps to mitigate further risk. Reuters sources identified Accenture as the service provider, but the FBI did not publicly name the company.
Mandiant reported renewed September attacks against organizations that had deployed web application firewall rules without installing Oracle's update. It assessed that ShinyHunters used URL encoding to bypass filtering of the PSEMHUB endpoint associated with CVE-2026-35273; the FBI did not confirm that vulnerability as its breach mechanism.
ShinyHunters claimed it exploited a PeopleSoft vulnerability to breach the FBI's job website. Reuters could not independently confirm the claimed entry route.
ShinyHunters said it would not publish the stolen FBI employee records but did not confirm deleting them. The statement left unresolved whether the group retained the sensitive information.
ShinyHunters allegedly leaked some stolen FBI employee information to the media. The attack reportedly sought to pressure the FBI into correcting or removing a warning report about the group, which ShinyHunters claimed contained false allegations.
Accenture told Reuters it would continue supporting the FBI's mission. It did not answer questions about the contractor or the alleged patching failure.
Reuters reported that suspected ShinyHunters member Saif al-Din Khader had been detained in Jordan and was cooperating with the FBI and other authorities. The FBI had not publicly confirmed his detention.
Two members of ShinyHunters were arrested. The FBI said its investigation was continuing with partners and could lead to further arrests.
A breach exposed personal details of thousands of FBI employees, including names of staff in sensitive units and medical and psychiatric records. Reuters sources identified the affected system as Oracle PeopleSoft, although the FBI did not publicly name the platform.
Oracle issued a patch in June for the PeopleSoft vulnerability described in Mandiant's findings on renewed ShinyHunters exploitation. The reference does not explicitly establish that this vulnerability was the FBI breach mechanism.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcehackread.com
Open sourcemalware.news
Open sourcemalware.news
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcereuters.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.