What’s confirmed and what isn’t. The FBI statement confirms a third-party-managed platform, a patch that had already been issued, and a removed contractor. Reuters reported the removal late Monday and named Accenture and PeopleSoft. Nextgov/FCW, citing one person familiar with the matter, reported that Accenture handles software patch management and custom code maintenance at the FBI, and that the unapplied patches came from Oracle. Nextgov says the stolen data included employees’ addresses, phone numbers, spouse details, information on intelligence and surveillance roles, and private medical information. Accenture’s only comment to SecurityWeek was that it is “proud to support the mission of the FBI and will continue to do so.”
The exploit question is still open. When ShinyHunters claimed the hack in September, it told BleepingComputer it used a new PeopleSoft zero-day. The FBI’s version, that a vendor fix existed and wasn’t applied, contradicts that. Separately, Mandiant has tracked ShinyHunters back in mass exploitation of CVE-2026-35273, the PeopleTools missing-authentication bug Oracle patched in June (CISA KEV since Jun 12, ransomware use flagged). The new trick is one URL-encoded character: request /%50SEMHUB/hub instead of /PSEMHUB/hub, the WAF’s literal-path rule misses it, and WebLogic decodes it straight to the vulnerable Environment Management Hub. Nobody has confirmed that this is the path into the FBI. It is the obvious first suspect.
What we’d check today if we run PeopleSoft. Confirm the June fix for CVE-2026-35273 is actually on every PeopleTools instance, including the ones a partner runs for you. If you don’t need PSEMHUB, disable it. Make sure your WAF or reverse proxy matches on decoded, normalized paths and not raw strings. Then grep WebLogic access logs for PSEMHUB, %50SEMHUB and mixed-case variants, especially short bursts of POSTs to /hub. A virtual patch at the edge that a single %50 gets past is the same as having no patch.
The buyer read. The FBI just said publicly that the managed-service provider owned the miss, and removed them. Every CISO who outsources ERP or HR platforms to a systems integrator should look at the contract today. Who owns the patch SLA, how many days does it allow for a KEV-listed bug, who verifies that the patch actually landed, and does anyone get notified when it slips? “The integrator handles patching” is not a control unless someone independently scans the box. For Accenture, the reputational hit lands on the managed-services business it sells to government and the Fortune 500. Contract or financial consequences beyond this one removal: Undisclosed.
Desk sheet: FBI says ShinyHunters breach stemmed from a contractor failing to apply an issued patch on a third-party-managed platform; contractor removed (FBI, Leatherman statement). Accenture and Oracle PeopleSoft named by Reuters, citing two sources. Accenture handled patch management and custom code, per a Nextgov source. Data exposed included addresses, phones, spouse info, intel/surveillance roles and medical info (Nextgov). CVE used against the FBI: unconfirmed. Related campaign: CVE-2026-35273 with a %50SEMHUB WAF bypass (Mandiant via BleepingComputer). Number of employees affected: Undisclosed.
