Breaking
Cyber CrimeConfirmed

FBI Ousts Contractor Over Missed Patch

FBI cyber chief says a third-party contractor failed to apply a security patch, enabling the ShinyHunters breach of employee data.

··1 hour ago·3 min read
White rectangular towers with copper wiring connected to a curved teal arch
Photo by Brecht Corbeel on Unsplash

The FBI has severed ties with an Accenture contractor after a data breach exposed personal information belonging to thousands of bureau employees, according to a Reuters report published Tuesday that cited two people familiar with the matter. A senior bureau official told Reuters the review so far points to a security patch that the contractor responsible for the affected system had not applied.

Patch failure blamed for breach

FBI cyber chief Brett Leatherman said in a statement that the incident stemmed from a security failure on a platform managed by an outside organization. The contractor, he said, failed to implement a patch that had been explicitly issued to secure the system.

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in a statement.

— Brett Leatherman, FBI cyber chief

Contractor removed and mitigation steps

Leatherman added that the bureau had taken action to reduce further exposure and protect its workforce.

“As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” Leatherman added.

The FBI has not publicly named the contractor or the organization involved. Reuters’ sources, however, identified the system as Oracle’s PeopleSoft human resources platform and the outside organization as Accenture.

Accenture response and prior warnings

Accenture did not answer questions about the contractor or the alleged patching failure. The company instead issued a statement saying it was “proud to support the mission of the FBI and will continue to do so.”

ShinyHunters had previously claimed it exploited PeopleSoft to break into the FBI’s job site. Google warned that the threat actor had been targeting vulnerable PeopleSoft instances to steal data. The group hacked FBI systems and announced on September 22 that it had done so, targeting the agency’s jobs website and allegedly obtaining information on all employees, including sensitive data, some of which it leaked to the media.

Pressure campaign and arrests

The attack allegedly aimed to pressure the FBI to correct or remove a report the agency published in May to warn organizations about ShinyHunters attacks. The hackers claimed the report made false allegations. Shortly after ShinyHunters announced the breach, law enforcement said it had arrested an alleged leader of the group in the Netherlands on September 15. ShinyHunters seemed defiant and urged victims to continue negotiating, threatening to leak their data unless they paid up.

The arrest of another alleged ShinyHunters leader, Saif al-Din Khader (aka Rey), came to light on October 3. Rey was reportedly arrested in Jordan and has been cooperating with authorities.

ShinyHunters site still online

At the time of writing, ShinyHunters’ website is still live, but a post urging organizations to pay up has been removed. The most recent victim post is dated September 22.

What the numbers show

  • Thousands of bureau employees had personal information exposed in the breach.
  • The ShinyHunters breach announcement was made on September 22.
  • An alleged leader of the group was arrested in the Netherlands on September 15.
  • The arrest of another alleged leader, Saif al-Din Khader (aka Rey), came to light on October 3.
  • The FBI report that ShinyHunters wanted corrected or removed was published in May.

Why it matters

For any organization that relies on third-party providers to manage core systems, this incident illustrates how a single unpatched platform can become the entry point for a damaging breach. The FBI’s decision to remove the contractor suggests that even when an outside party is responsible for the technical failure, the consequences for the relationship can be immediate. As more details emerge — and as ShinyHunters continues to operate, with its site still live — the episode could prompt other agencies and companies to reassess how they verify that critical patches are actually deployed by their contractors.

#fbi#shinyhunters#accenture#peoplesoft#data breach#patching

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories