The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor following an internal review into a ShinyHunters cyber breach that resulted in the exposure of personal information belonging to thousands of bureau employees. The development comes after investigators determined that the incident was linked to a security failure involving a third party managed platform, where a required security patch had not been implemented. The FBI said it has taken additional measures to reduce potential risks and strengthen protection for its workforce following the incident.
According to a Reuters report citing sources familiar with the matter, the FBI identified the issue as being connected to a security failure involving a platform managed by an external organization. Brett Leatherman, Assistant Director of FBI’s Cyber Division, told Reuters that the review found the incident occurred after a contractor failed to apply a security patch that had been specifically issued to protect the platform. The FBI stated that the contractor was removed after the review and that additional steps were taken to address security concerns and prevent further risks. While the FBI did not publicly name the third party organization involved, Reuters reported that the affected platform was Oracle PeopleSoft, which the ShinyHunters group claimed was used during the attack against the bureau’s job portal.
Security researchers have linked the incident to exploitation activity involving a vulnerability affecting Oracle systems. According to analysis from Google owned Mandiant, ShinyHunters was reportedly exploiting a bypass technique associated with CVE-2026-35273 by using URL encoding methods to evade a web application firewall (WAF) rule designed to block access to a vulnerable Environment Management Hub endpoint. Researchers stated that the technique allowed attackers to reach the targeted system despite existing security controls. The vulnerability and exploitation activity highlight the importance of timely patch deployment, continuous monitoring, and effective security management across third party platforms that support critical organizational operations. Accenture, which provides services to multiple organizations including government entities, responded to Reuters by stating that it remains committed to supporting the FBI’s mission. The company said it would continue providing support while the investigation and security response efforts continue. The FBI has not disclosed additional details regarding the contractor involved or the full scope of the internal review. The agency continues working with partners to investigate the incident, gather further information, and pursue additional leads related to the breach.
The incident represents another development in the ongoing investigation into ShinyHunters, a cybercrime group that has been associated with multiple data exposure incidents. The FBI previously confirmed that two individuals connected to the group had been taken into custody as part of broader investigative efforts and indicated that further enforcement actions could follow. The case highlights the growing security challenges organizations face when managing complex technology environments involving third party providers, highlighting the need for strong patch management practices, vendor security oversight, and proactive vulnerability management to protect sensitive information.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.