FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees. That's according to a report from Reuters, citing two sources familiar with the matter. "To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform," Brett Leatherman, assistant director of the FBI's cyber division, was quoted as saying to the FBI. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month. According to a report from Google-owned Mandiant, ShinyHunters is assessed to be exploiting a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint. The Hacker News has contacted both the FBI and Oracle for comment, and we will update the story if we hear back. Accenture, in a statement shared with Reuters, said it was "proud to support the mission of the FBI and will continue to do so." The development is the latest twist in the operational history of ShinyHunters, which has had two of its members arrested as the FBI continues its investigation into the breach. The agency said it's actively working with partners to obtain and execute more leads, and warned more arrests are likely to come. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Original Source

Read the full article at Thehackernews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.