Accenture contractor removed from FBI after data leak that exposed personal details of thousands of bureau employees, comes weeks after Google’s ‘warning’
FBI cyber chief Brett Leatherman confirmed that an unidentified contractor had failed to properly update the system.
“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said in a statement to Reuters. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” he added. However, two sources familiar with the matter told Reuters that the platform was Oracle’s PeopleSoft, a human resources system. The hacking group ShinyHunters has said it used a PeopleSoft weakness to break into the FBI’s job site last month. The two sources told Reuters that Accenture was the third-party organisation managing the platform.
The FBI did not name the platform or the third-party company.
The contractor was removed on Monday, October 5 after the FBI found that a security patch had not been properly installed on a platform managed by a third party.
The FBI has removed an Accenture contractor after a data breach exposed sensitive personal information of thousands of bureau employees, two sources familiar with the matter told Reuters. As per the report, the FBI breach comes weeks after Google warned about a hacking and extortion campaign linked to ShinyHunters targeting organisations that use PeopleSoft software. As stated above, the FBI breach comes after Google warned about a hacking and extortion campaign linked to ShinyHunters targeting organisations that use PeopleSoft software in June this year. The tech giant then raised the alarm about the campaign. Oracle issued a security alert on the same day, identifying a weakness in PeopleSoft and offering security fixes. Both companies urged organisations using PeopleSoft to “apply all Critical Patch Updates, Critical Security Patch Updates and Security Alerts without delay. You use AI every day. Now get your AI Quotient. Take the AIQ test.
The stolen information included detailed descriptions of named employees’ counterintelligence jobs, street addresses of human intelligence operatives, and medical and psychiatric records of FBI workers, according to the Reuters report. The FBI is still assessing the full impact of the breach, which exposed sensitive information including details of employees’ counterintelligence work, addresses of human intelligence operatives, and medical and psychiatric records, the report stated. ShinyHunters has credited a vulnerability in PeopleSoft for helping it gain access to the system.

