The FBI has removed an Accenture contractor after a review found that a required security patch was never applied on a platform run by a third party. The bureau's cyber division said that failure led to a breach in which personal details of thousands of FBI employees were taken. Reuters reported the platform as Oracle PeopleSoft, the same product ShinyHunters has been hitting.
What happened
Assistant director Brett Leatherman said the incident was a security failure on a third-party platform after a contractor did not implement a patch that had been explicitly issued. The FBI did not name the platform. Reuters did, citing sources, and tied it to the PeopleSoft job-portal intrusion ShinyHunters claimed in September.
Mandiant has assessed that the group is still getting around a firewall rule meant to block the vulnerable PeopleSoft endpoint for CVE-2026-35273. A block rule that the attacker can step around is not remediation. Accenture told Reuters it remains proud to support the FBI. The same investigation has already produced arrests.
Who is affected
This is a vendor-control failure, not a new bug disclosed today. It matters to any organisation that outsources patching of an internet-facing ERP, HR, or job portal.
- FBI: contractor removed, patch miss confirmed by the bureau
- Platform name: Oracle PeopleSoft, per Reuters, not stated by the FBI
- Related bug still in play: CVE-2026-35273, with a reported firewall bypass
What to do now
If a contractor manages PeopleSoft or any other internet-facing business system, confirm the vendor patch is installed. Do not accept a firewall rule as the close-out. Ask for the build, the install date, and evidence the vulnerable endpoint no longer answers. Then check whether your own ERP, HR, and recruitment portals have the same gap between a closed ticket and a patched box.
Source: The Hacker News, 6 October 2026, citing Reuters. FBI removes Accenture contractor after patch failure led to ShinyHunters breach.
Also on the blog
- Atlassian CVE-2026-21589: unauthenticated file read on 8 products
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- Rejetto HFS CVE-2026-61500: scanners forging admin sessions, CVSS 9.3
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.