Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

FBI removes Accenture contractor after missed security patch led to breach

Дата публикации: 06-10-2026 14:08:00

The bureau’s cyber chief blamed a contractor’s failure to apply an available fix for an intrusion that may have exposed sensitive employee information.

Основное содержимое страницы с новостью.

860x394.jpg?1791297931

Joan Cros/NurPhoto via Getty Images

David DiMolfetta By David DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW

By David DiMolfetta

| October 6, 2026

The bureau’s cyber chief blamed a contractor’s failure to apply an available fix for an intrusion that may have exposed sensitive employee information.

The FBI has severed ties with a contractor working for Accenture amid a massive cybercrime intrusion that may have exposed data on thousands of bureau employees, according to a person with knowledge of the matter.

Prolific cybercrime group ShinyHunters claimed responsibility for the hack last month. The data stolen contained employees’ addresses, phone numbers and information on their spouses, among other categories. It also revealed sensitive data on employees’ intelligence and surveillance roles, as well as private medical information.

Accenture is responsible for software patch management and maintaining custom code at the FBI, said the person, who spoke on the condition of anonymity because the situation is sensitive. Oracle — whose PeopleSoft platform was the initial access point that ShinyHunters claimed to have exploited — provided the security patches that were not integrated, the person added.

FBI cybersecurity chief Brett Leatherman confirmed the removal of an unnamed contractor in a statement to Nextgov/FCW.

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”

The remarks offer the bureau’s clearest explanation yet of how the intrusion occurred, though they do not address why the patch was missed and how the FBI monitored the contractor’s work to ensure systems holding sensitive employee information were protected.

Reuters first reported the removal late Monday. The specific Accenture employee could not be immediately identified.

In a statement, the company said it’s “proud to support the mission of the FBI and will continue to do so.”

The breach follows recent findings from Google’s Mandiant that ShinyHunters had resumed widespread exploitation of a PeopleSoft vulnerability for which Oracle issued a patch in June. 

The incident poses serious counterintelligence risks because the exposed records could help foreign intelligence services identify employees working on sensitive investigations and exploit personal information about them. 

ShinyHunters has said it would not publish the stolen data, but its statement did not say the records had been deleted. Retired Lt. Gen. Robert Skinner, who previously led the Defense Information Systems Agency, told Nextgov/FCW last week that the group could still sell some or all of the information to foreign intelligence services or other buyers.

Authorities have also moved against suspected members of the group. Dutch police last week announced the arrest of an alleged leader, and Reuters reported Saturday that another suspected member, Saif al-Din Khader, had been detained in Jordan and was helping investigators locate other hackers.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Reuters: ФБР отстранило подрядчика после утечки данных тысяч сотрудников08.0406-10-2026
2ФБР отстранило подрядчика из-за инцидента с хищением данных, пишут СМИ010.9506-10-2026
3ФБР отстранило подрядчика из-за хищения данных сотрудников010.9606-10-2026
4FBI investigates hackers' claim to have stolen sensitive employee data, compromised jobs website05.8323-09-2026
5FBI wird gehackt – Cyberkriminelle entwenden heikle Personaldaten und Informationen zu Geheimaufträgen09.8630-09-2026
6ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles06.5824-09-2026
7Two Federal Breaches Expose Millions of Sensitive Records in Rapid Succession011.8902-10-2026
8Stolen FBI data reveals employees’ roles in intelligence and surveillance07.7924-09-2026
9FBI Sounds Alarm as FortiBleed Campaign Persists, Locking Firms Out of Their Own Firewalls010.407-10-2026
10Revolut breach exposes authentication-authorization gap018.8617-09-2026

Классификация: Происшествия. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.86. Источник: fcw.com.