Accenture contractor removed from FBI following damaging data breach, sources say
ACN•The FBI removed an Accenture contractor after a breach exposed sensitive personal information of thousands of bureau employees. The FBI said the contractor failed to install a security patch; sources identified the affected platform as Oracle PeopleSoft.
1. FBI removes contractor
The FBI removed an unidentified contractor on Monday over a security failure that exposed sensitive personal details of thousands of bureau employees. FBI cyber chief Brett Leatherman said the contractor failed to implement a security patch explicitly issued to secure the platform, and the bureau had taken steps to mitigate further risk and protect its workforce.
2. PeopleSoft identified
The FBI did not name the platform or third-party organization. Two sources identified the system as Oracle PeopleSoft and the platform manager as Accenture. The breach exposed job details, addresses and medical and psychiatric records, including information about counterintelligence roles and human intelligence operatives.
3. Security warnings issued
Google raised an alarm in June over a ShinyHunters-linked hacking and extortion campaign targeting organizations using PeopleSoft. Oracle issued a security alert and offered fixes the same day; both companies urged organizations to apply security updates without delay. ShinyHunters credited a PeopleSoft vulnerability for facilitating the intrusion.




