The FBI has removed a contractor after determining that a failure to install a security patch led to the September breach of a third-party-managed platform. ShinyHunters claimed responsibility for the intrusion, which exposed sensitive information on thousands of bureau employees, according to Reuters.
The contractor was removed from work for the FBI on Monday, October 5, after the bureau's review found that a security update intended to protect the affected platform had not been installed.
FBI Cyber Division Assistant Director Brett Leatherman said the contractor had “failed to implement a security patch explicitly issued to secure the platform.” He said the bureau had since taken steps to reduce further risk and protect its workforce.
The FBI did not publicly identify either the affected platform or the third-party organisation managing it. However, two sources familiar with the investigation told Reuters that the system was Oracle PeopleSoft and that the third-party organisation was Accenture.
Reuters could not identify the individual contractor or determine their current employment status. Accenture confirmed that it supports the FBI and said that support would continue, but did not answer questions about the contractor or the alleged failure to install the patch. Oracle did not immediately respond to Reuters' request for comment.
ShinyHunters previously said a vulnerability in Oracle PeopleSoft helped it gain access to the FBI's recruitment website, FBIjobs.gov. The group claimed responsibility for the September intrusion, while the FBI said it was investigating unauthorised activity affecting the site.
Oracle issued a security alert on June 10 for CVE-2026-35273, a critical PeopleSoft PeopleTools vulnerability that can allow an unauthenticated attacker to remotely compromise an affected system. Mandiant and Google Threat Intelligence Group said ShinyHunters had exploited the flaw as a zero-day between May 27 and June 9, before the patch was available.
Google warned again in September that ShinyHunters had resumed widespread exploitation of CVE-2026-35273, including against systems whose operators had relied on web application firewall rules rather than installing Oracle's security update.
However, the FBI has not publicly identified CVE-2026-35273 as the specific vulnerability used in its breach. Reuters said it had not been able to determine whether or when those responsible for securing the site followed the earlier patching recommendations.
Reuters reported that data exposed in the breach included highly sensitive information, including detailed descriptions of named employees' counterintelligence roles, street addresses of people working in human intelligence, and medical and psychiatric records belonging to bureau employees.
