thehackernews.com 6 Oct 2026, 06:56 UTC

FBI removes Accenture contractor after ShinyHunters breach exposes staff data

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

THE FBI has removed an Accenture contractor following a security lapse linked to a ShinyHunters data breach that exposed personal details of thousands of FBI employees. Reuters, citing two sources, reports that the incident stemmed from a security failure in a platform managed by a third party, after the contractor failed to implement a patch explicitly issued to secure the platform. The FBI said it had mitigated further risk and protected its workforce as part of the steps taken.

The breach is associated with ShinyHunters’ attacks on Oracle PeopleSoft, which the group claims it exploited to breach the FBI’s job portal. Mandiant assessments cited by Google’s parent company suggest the attackers bypassed a web application firewall using a URL-encoding technique to exploit a bypass for CVE-2026-35273 affecting the Environment Management Hub (PSEMHUB) endpoint. The FBI has not named the third-party vendor in its statements; Reuters notes the connection to Oracle PeopleSoft.

The FBI states the contractor’s removal is part of ongoing measures, with further arrests anticipated as the investigation into ShinyHunters continues and more leads are pursued. Accenture has said it remains proud to support the FBI’s mission.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline