FBI reportedly removes contractor over employee data breach
The FBI on Monday removed an Accenture contractor after a contractor failed to apply a security patch on a third-party platform. FBI cyber chief Brett Leatherman said the incident resulted from that failure. He said the bureau has removed the contractor and taken steps to mitigate further risk and protect its workforce. The FBI has not named the platform or vendor. Sources identified them as Oracle PeopleSoft and Accenture. ShinyHunters claimed it exploited a PeopleSoft vulnerability to access the FBI job site last month; exposed data reportedly included job details, street addresses of human intelligence operatives, and medical and psychiatric records. The group said the attack was revenge over a May FBI advisory, not for ransom. Oracle issued a June security alert and patch after a Google warning. CVE-2026-35273 was exploited between May 27 and June 9, 2026, affecting over 300 instances across 100 organizations. Amazon's One Medical Senior Health and Nissan confirmed they were hit in the broader campaign. Two ShinyHunters suspects have been arrested, one in Jordan and one in the Netherlands. Accenture said it is proud to support the FBI mission and will continue to do so. Accenture separately disclosed a June breach in which alias 888 claimed theft of 35GB of data.
Where do you stand?







