BREAKING · BREACH

FBI says a contractor’s missed patch let ShinyHunters in. Reuters says the contractor was Accenture’s, and the system was PeopleSoft

The FBI has given its clearest account yet of the ShinyHunters breach that exposed personal details of thousands of bureau employees. FBI cyber chief Brett Leatherman said the incident “occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” and that the bureau “has removed the contractor.” The FBI didn’t name anyone. Reuters, citing two sources, reported the contractor worked for Accenture and the platform is Oracle PeopleSoft. Accenture didn’t answer questions about the patch. Records affected, which CVE was used, and who owned the patch SLA in the contract: Undisclosed.

Oct 6, 2026 · 3 min read

What’s confirmed and what isn’t. The FBI statement confirms a third-party-managed platform, a patch that had already been issued, and a removed contractor. Reuters reported the removal late Monday and named Accenture and PeopleSoft. Nextgov/FCW, citing one person familiar with the matter, reported that Accenture handles software patch management and custom code maintenance at the FBI, and that the unapplied patches came from Oracle. Nextgov says the stolen data included employees’ addresses, phone numbers, spouse details, information on intelligence and surveillance roles, and private medical information. Accenture’s only comment to SecurityWeek was that it is “proud to support the mission of the FBI and will continue to do so.”

The exploit question is still open. When ShinyHunters claimed the hack in September, it told BleepingComputer it used a new PeopleSoft zero-day. The FBI’s version, that a vendor fix existed and wasn’t applied, contradicts that. Separately, Mandiant has tracked ShinyHunters back in mass exploitation of CVE-2026-35273, the PeopleTools missing-authentication bug Oracle patched in June (CISA KEV since Jun 12, ransomware use flagged). The new trick is one URL-encoded character: request /%50SEMHUB/hub instead of /PSEMHUB/hub, the WAF’s literal-path rule misses it, and WebLogic decodes it straight to the vulnerable Environment Management Hub. Nobody has confirmed that this is the path into the FBI. It is the obvious first suspect.

What we’d check today if we run PeopleSoft. Confirm the June fix for CVE-2026-35273 is actually on every PeopleTools instance, including the ones a partner runs for you. If you don’t need PSEMHUB, disable it. Make sure your WAF or reverse proxy matches on decoded, normalized paths and not raw strings. Then grep WebLogic access logs for PSEMHUB, %50SEMHUB and mixed-case variants, especially short bursts of POSTs to /hub. A virtual patch at the edge that a single %50 gets past is the same as having no patch.

The buyer read. The FBI just said publicly that the managed-service provider owned the miss, and removed them. Every CISO who outsources ERP or HR platforms to a systems integrator should look at the contract today. Who owns the patch SLA, how many days does it allow for a KEV-listed bug, who verifies that the patch actually landed, and does anyone get notified when it slips? “The integrator handles patching” is not a control unless someone independently scans the box. For Accenture, the reputational hit lands on the managed-services business it sells to government and the Fortune 500. Contract or financial consequences beyond this one removal: Undisclosed.

Desk sheet: FBI says ShinyHunters breach stemmed from a contractor failing to apply an issued patch on a third-party-managed platform; contractor removed (FBI, Leatherman statement). Accenture and Oracle PeopleSoft named by Reuters, citing two sources. Accenture handled patch management and custom code, per a Nextgov source. Data exposed included addresses, phones, spouse info, intel/surveillance roles and medical info (Nextgov). CVE used against the FBI: unconfirmed. Related campaign: CVE-2026-35273 with a %50SEMHUB WAF bypass (Mandiant via BleepingComputer). Number of employees affected: Undisclosed.

Sources