Back to News
News · Cybersecurity

FBI Removes Accenture Contractor After ShinyHunters Breach

A missed patch on a third-party platform let attackers reach FBI employee and job-applicant data.

Source: The Hacker News · October 6, 2026

The Hacker News reports that the FBI has removed an Accenture contractor over a security failure that let the ShinyHunters group breach a bureau job portal running on Oracle PeopleSoft, stealing personal details on employees and job applicants. According to Brett Leatherman, assistant director of the FBI's cyber division, the contractor failed to implement a security patch that had been explicitly issued to secure the platform. ShinyHunters is assessed to have exploited a bypass for CVE-2026-35273, using a URL-encoding trick to get around a web application firewall rule meant to block the vulnerable Environment Management Hub endpoint.

The FBI says it has taken steps to mitigate further risk and protect its workforce, and that two ShinyHunters members have already been arrested, with more expected.

Why it matters: the breach traces back to an unpatched third-party vendor platform, a reminder that enterprise security postures are only as strong as the contractors and SaaS systems they depend on. Track vendor patch compliance as closely as your own, and treat known WAF bypass techniques as a reason to patch the underlying flaw, not just tune the rule.