FBI removes Accenture contractor after missed PeopleSoft patch
ShinyHunters theft of FBI employee data tied to a third-party patch failure

FBI removes Accenture contractor after missed PeopleSoft patch

The FBI removed an Accenture contractor on Monday after a breach that exposed personal details of thousands of bureau employees. Reuters reported the removal on 6 October 2026, citing two sources familiar with the matter.

FBI cyber chief Brett Leatherman said the incident followed a security failure on a platform managed by a third party, after a contractor failed to implement a patch that had been explicitly issued. The FBI did not name the company or the product. Reuters' sources identified the platform as Oracle PeopleSoft and the third party as Accenture.

What happened

ShinyHunters has said it used a PeopleSoft flaw to reach the FBI jobs portal. Reporting on the latest development ties that intrusion to a missed patch, not to a novel exploit. Exposed material described in coverage includes job details, addresses, and medical records of bureau staff. The FBI says it is still assessing impact and has taken steps to limit further risk.

Accenture told Reuters it was proud to support the FBI and would continue to do so. Reuters could not identify the individual contractor. Treat the company and product names as sourced to Reuters' unnamed officials, not as an FBI press release.

Who is affected

Directly, FBI employees whose data was on the affected HR platform. For everyone else, the lesson is vendor-operated identity and HR systems. A patch SLA that is not enforced is an incident waiting on a calendar.

What to do now

  • List every vendor-managed HR, identity, and jobs platform and confirm the last applied security patch against the vendor advisory.
  • Write patch deadlines into the contract, with evidence the vendor must produce, not a status email.
  • If a third party runs PeopleSoft or a similar HR suite, ask whether CVE-class patches from the last quarter are installed.
  • Assume employee data on an unpatched HR portal is in scope for extortion groups. Restrict portal exposure and watch for bulk exports.

Source: Reuters, 6 October 2026. Read the report.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-88779: NetScaler SAML crash, KEV due 7 October
Memory overflow in NetScaler ADC and Gateway SAML, actively exploited