Anonymous ID: 645541 Oct. 6, 2026, 2:05 p.m. No.25112649   🗄️.is 🔗kun   >>2757

FBI removes Accenture contractor after missed security patch led to breach

 

The FBI has severed ties with a contractor working for Accenture amid a massive cybercrime intrusion that may have exposed data on thousands of bureau employees, according to a person with knowledge of the matter.

 

Prolific cybercrime group ShinyHunters claimed responsibility for the hack last month. The data stolen contained employees’ addresses, phone numbers and information on their spouses, among other categories. It also revealed sensitive data on employees’ intelligence and surveillance roles, as well as private medical information.

 

Accenture is responsible for software patch management and maintaining custom code at the FBI, said the person, who spoke on the condition of anonymity because the situation is sensitive. Oracle — whose PeopleSoft platform was the initial access point that ShinyHunters claimed to have exploited — provided the security patches that were not integrated, the person added.

 

FBI cybersecurity chief Brett Leatherman confirmed the removal of an unnamed contractor in a statement to Nextgov/FCW.

 

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”

 

 

https://www.govexec.com/technology/2026/10/fbi-removes-accenture-contractor-after-missed-security-patch-led-breach/416446/