www.securityweek.com 6 Oct 2026, 14:15 UTC

FBI Removes Accenture Contractor After Employee Data Breach

FBI Removes Accenture Contractor After Employee Data Breach
CyberSIXT Evidence Panel
Threat Actor

THE FBI has removed an Accenture contractor after a data breach that exposed personal information of thousands of FBI employees. Reuters, citing two familiar sources, says the incident was linked to a security patch that the contractor responsible for the affected system failed to apply. FBI cyber chief Brett Leatherman said the breach resulted from a security failure of a platform managed by a third party, and that steps have been taken to mitigate risk and protect the workforce.

The system involved is reportedly Oracle’s PeopleSoft human resources platform, with Accenture identified as the external organisation involved. ShinyHunters had previously claimed it exploited PeopleSoft to access FBI data, and Google warned that the threat actor had been targeting vulnerable PeopleSoft instances. The article notes that the FBI has not named the contractor or the organisation publicly.

ShinyHunters announced the breach on 22 September and has since faced arrests related to the operation, with another leader reportedly arrested in Jordan on 3 October. At the time of reporting, the ShinyHunters site remained live, though a post urging victims to pay had been removed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline