Back to Feed
BreachesOct 6, 2026

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

FBI removes Accenture contractor after patch failure led to ShinyHunters breach.

Summary

The FBI has removed an Accenture contractor following a security failure that led to a data breach by the ShinyHunters group. The breach, which compromised the FBI's job portal and exposed personal details of thousands of employees, occurred because a contractor failed to apply a critical security patch to an Oracle PeopleSoft platform. ShinyHunters exploited a vulnerability related to CVE-2026-35273 to bypass security measures.

Full text

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach Ravie LakshmananOct 06, 2026 The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform," Brett Leatherman, assistant director of the FBI's cyber division, was quoted as saying to the FBI. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month. According to a report from Google-owned Mandiant, ShinyHunters is assessed to be exploiting a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint. The Hacker News has contacted both the FBI and Oracle for comment, and we will update the story if we hear back. Accenture, in a statement shared with Reuters, said it was "proud to support the mission of the FBI and will continue to do so." The development is the latest twist in the operational history of ShinyHunters, which has had two of its members arrested as the FBI continues its investigation into the breach. The agency said it's actively working with partners to obtain and execute more leads, and warned more arrests are likely to come. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cybercrime, data breach, oracle, Vulnerability, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills

Indicators of Compromise

  • cve — CVE-2026-35273

Entities

ShinyHunters (threat_actor)Accenture (vendor)Oracle PeopleSoft (product)Environment Management Hub (product)FBI (vendor)