Back to Newsroom
Breach

FBI Cuts Ties With Contractor After Unpatched Oracle Flaw Leads to Staff Data Breach

A missed security patch on a third-party Oracle PeopleSoft platform let the ShinyHunters group steal personal data on thousands of FBI employees — and cost the vendor its contract.

FBI Cuts Ties With Contractor After Unpatched Oracle Flaw Leads to Staff Data Breach

What happened

The FBI has ended its relationship with an Accenture contractor after the firm failed to apply a security patch to an Oracle PeopleSoft platform used to manage bureau employee records, according to a Reuters report citing two people familiar with the matter. The unpatched system became the entry point for the ShinyHunters group, which stole personal details — including pay and contact information — belonging to thousands of FBI staff through the agency's job portal.

Brett Leatherman, assistant director of the FBI's cyber division, said the bureau's review traced the incident to "a security failure of a platform managed by a third-party organization" after the contractor "failed to implement a security patch explicitly issued to secure the platform." The FBI said it has removed the contractor and taken steps to mitigate further risk. Accenture, in a statement to Reuters, said it remains "proud to support the mission of the FBI."

Why it matters

According to an assessment from Mandiant, ShinyHunters is believed to have bypassed CVE-2026-35273 using a URL-encoding trick that slipped past a web application firewall rule meant to shield the vulnerable Environment Management Hub (PSEMHUB) endpoint. That detail matters beyond this one incident: a WAF rule is a compensating control, not a fix, and encoding tricks are one of the oldest ways to defeat one. When the underlying patch doesn't ship, the control protecting it eventually gets found and worked around.

The breach also lands squarely on the question of vendor accountability. The exposed data sat on a bureau system, but the failure originated with a contractor's patch management — a reminder that outsourcing platform operations doesn't outsource the risk.

This is the latest chapter in ShinyHunters' run: two of the group's members have already been arrested, and the FBI says it is working with partners to identify and pursue more.

What to do

  • Patch Oracle PeopleSoft deployments against CVE-2026-35273 now — treat any WAF rule covering it as a stopgap, not a solution.
  • Re-test WAF and filtering rules against encoding bypasses (URL-encoding, double-encoding, case variation) on any endpoint your compensating controls are protecting.
  • Require contractors and platform vendors to prove patch application on a defined cadence, not just commit to one — vendor-managed systems are still part of your attack surface.
  • Watch for anomalous access to HR and employee-data stores, which are increasingly a direct target when business platforms are compromised.
SHARE