FBI Ousts Contractor Over Missed Patch
FBI cyber chief says a third-party contractor failed to apply a security patch, enabling the ShinyHunters breach of employee data.
The FBI has severed ties with an Accenture contractor after a data breach exposed personal information belonging to thousands of bureau employees, according to a Reuters report published Tuesday that cited two people familiar with the matter. A senior bureau official told Reuters the review so far points to a security patch that the contractor responsible for the affected system had not applied.
Patch failure blamed for breach
FBI cyber chief Brett Leatherman said in a statement that the incident stemmed from a security failure on a platform managed by an outside organization. The contractor, he said, failed to implement a patch that had been explicitly issued to secure the system.
“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in a statement.
— Brett Leatherman, FBI cyber chief
Contractor removed and mitigation steps
Leatherman added that the bureau had taken action to reduce further exposure and protect its workforce.
“As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” Leatherman added.
The FBI has not publicly named the contractor or the organization involved. Reuters’ sources, however, identified the system as Oracle’s PeopleSoft human resources platform and the outside organization as Accenture.
Accenture response and prior warnings
Accenture did not answer questions about the contractor or the alleged patching failure. The company instead issued a statement saying it was “proud to support the mission of the FBI and will continue to do so.”
ShinyHunters had previously claimed it exploited PeopleSoft to break into the FBI’s job site. Google warned that the threat actor had been targeting vulnerable PeopleSoft instances to steal data. The group hacked FBI systems and announced on September 22 that it had done so, targeting the agency’s jobs website and allegedly obtaining information on all employees, including sensitive data, some of which it leaked to the media.
Pressure campaign and arrests
The attack allegedly aimed to pressure the FBI to correct or remove a report the agency published in May to warn organizations about ShinyHunters attacks. The hackers claimed the report made false allegations. Shortly after ShinyHunters announced the breach, law enforcement said it had arrested an alleged leader of the group in the Netherlands on September 15. ShinyHunters seemed defiant and urged victims to continue negotiating, threatening to leak their data unless they paid up.
The arrest of another alleged ShinyHunters leader, Saif al-Din Khader (aka Rey), came to light on October 3. Rey was reportedly arrested in Jordan and has been cooperating with authorities.
ShinyHunters site still online
At the time of writing, ShinyHunters’ website is still live, but a post urging organizations to pay up has been removed. The most recent victim post is dated September 22.
What the numbers show
- Thousands of bureau employees had personal information exposed in the breach.
- The ShinyHunters breach announcement was made on September 22.
- An alleged leader of the group was arrested in the Netherlands on September 15.
- The arrest of another alleged leader, Saif al-Din Khader (aka Rey), came to light on October 3.
- The FBI report that ShinyHunters wanted corrected or removed was published in May.
Why it matters
For any organization that relies on third-party providers to manage core systems, this incident illustrates how a single unpatched platform can become the entry point for a damaging breach. The FBI’s decision to remove the contractor suggests that even when an outside party is responsible for the technical failure, the consequences for the relationship can be immediate. As more details emerge — and as ShinyHunters continues to operate, with its site still live — the episode could prompt other agencies and companies to reassess how they verify that critical patches are actually deployed by their contractors.
Sources
- SecurityWeek Original source
- warned Also reporting
- hacked FBI systems Also reporting
- defiant Also reporting
- arrest Also reporting
Continue Reading
DNS Hijack Undercuts TLS Trust
Attackers seized three country-code domains to mint counterfeit TLS certificates for Google and other brands, Google says.
Backdoors Hide Behind Email Security Brands
Rapid7 says Linux implants in South Korea and Taiwan impersonate SpamSniper and ShareTech to slip past defenders.
Nikkei Email Breaches Expose 1,646 People
Nikkei says attackers hit a Google Workspace account in July and a Microsoft 365 account in September, later sending 9,000 phishing emails.