The FBI removed a contractor after an internal review linked a breach exposing sensitive personal information about thousands of employees to a missed security patch on a third-party-managed platform. FBI cyber division assistant director Brett Leatherman said the contractor failed to implement an explicitly issued patch. Sources cited by Reuters identified Accenture as the service provider and Oracle PeopleSoft as the affected platform, although the FBI did not publicly name either company. Earlier reporting described exposed employee names from sensitive units, along with medical and psychiatric records.
ShinyHunters claimed it breached the FBI’s job website through a PeopleSoft vulnerability, but Reuters could not confirm that entry route, and the FBI did not identify an exploited CVE. Separately, Mandiant assessed that ShinyHunters was using URL encoding to bypass a web application firewall rule blocking the vulnerable PSEMHUB endpoint associated with CVE-2026-35273; that observation provides context, not confirmation of the FBI breach mechanism. Two ShinyHunters members have been arrested, and the FBI said its continuing investigation could lead to further arrests. The incident underscores the need to verify third-party patch deployment rather than rely solely on contractor assurances or WAF protections.

See which actors are running it and whether you're in range.
12 events from the most recent confirmed update back to the earliest known activity.
FBI Director Kash Patel announced that agents had arrested another suspected ShinyHunters co-conspirator earlier that week as part of the ongoing investigation. The New York Times reported that the suspect was a Canadian national arrested in Pennsylvania; the FBI provided no additional details.
The FBI removed a contractor after its review attributed the breach to failure to install an explicitly issued security patch, and took steps to mitigate further risk. Reuters sources identified Accenture as the service provider, but the FBI did not publicly name the company.
Mandiant reported renewed September attacks against organizations that had deployed web application firewall rules without installing Oracle's update. It assessed that ShinyHunters used URL encoding to bypass filtering of the PSEMHUB endpoint associated with CVE-2026-35273; the FBI did not confirm that vulnerability as its breach mechanism.
ShinyHunters claimed it exploited a PeopleSoft vulnerability to breach the FBI's job website. Reuters could not independently confirm the claimed entry route.
ShinyHunters said it would not publish the stolen FBI employee records but did not confirm deleting them. The statement left unresolved whether the group retained the sensitive information.
ShinyHunters allegedly leaked some stolen FBI employee information to the media. The attack reportedly sought to pressure the FBI into correcting or removing a warning report about the group, which ShinyHunters claimed contained false allegations.
Accenture told Reuters it would continue supporting the FBI's mission. It did not answer questions about the contractor or the alleged patching failure.
Reuters reported that suspected ShinyHunters member Saif al-Din Khader had been detained in Jordan and was cooperating with the FBI and other authorities. The FBI had not publicly confirmed his detention.
Two members of ShinyHunters were arrested. The FBI said its investigation was continuing with partners and could lead to further arrests.
A breach exposed personal details of thousands of FBI employees, including names of staff in sensitive units and medical and psychiatric records. Reuters sources identified the affected system as Oracle PeopleSoft, although the FBI did not publicly name the platform.
Oracle issued a patch in June for the PeopleSoft vulnerability described in Mandiant's findings on renewed ShinyHunters exploitation. The reference does not explicitly establish that this vulnerability was the FBI breach mechanism.
The article reports that ShinyHunters began exploiting PeopleSoft vulnerability CVE-2026-35273 as a zero-day in late May, before Oracle issued a warning and an emergency patch in June. It does not establish that this initial exploitation targeted the FBI.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
20 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcesecuritymagazine.com
Open sourceheise.de
Open sourceitpro.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcelawfaremedia.org
Open sourcereuters.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.