The FBI says a third-party contractor failed to install a security patch before attackers breached its recruitment infrastructure and stole sensitive personnel information, providing the clearest explanation yet for how the ShinyHunters-linked intrusion occurred.
FBI Cyber Division Assistant Director Brett Leatherman said the bureau’s review determined that a contractor failed to implement a security patch that had been explicitly issued to protect the affected platform. The FBI subsequently removed the contractor and took additional steps to mitigate risk.
Reuters, citing 2 sources familiar with the incident, identified the contractor’s employer as Accenture and the affected technology as Oracle PeopleSoft. The FBI has not publicly named Accenture as the contractor’s employer.
The finding marks a significant development from the FBI’s initial disclosure in September, when the bureau said it had not yet determined whether the compromise originated within an FBI environment or through a third-party provider supporting FBIJobs.gov.
Missed patch emerges as key security failure
The FBIJobs.gov breach became public in September after ShinyHunters claimed it compromised the recruitment platform and obtained sensitive information involving current and former FBI personnel and job applicants.
BreachNews initially reported that the FBI was investigating the FBIJobs.gov intrusion after ShinyHunters claimed Oracle PeopleSoft vulnerabilities provided access to the environment.
At the time, the FBI confirmed it was investigating the compromise but said the point of breach remained undetermined.
The bureau’s subsequent review has now identified the failure to install a security update as the underlying security lapse that enabled the intrusion, according to Leatherman.
Reuters reported that the contractor responsible worked for Accenture, which provides technology services to the federal government. Accenture told Reuters it remains committed to supporting the FBI but did not address questions concerning the individual contractor or the reported failure to install the patch.
The FBI has not disclosed when the patch should have been deployed, how long the affected system remained vulnerable or whether additional security controls should have prevented exploitation after the update was missed.
PeopleSoft flaw had an emergency security update
The identification of Oracle PeopleSoft adds new context to ShinyHunters’ earlier claims about how it accessed FBI recruitment infrastructure.
Oracle issued an out-of-band security alert for CVE-2026-35273 on June 10. The critical PeopleSoft Enterprise PeopleTools vulnerability carries a CVSS score of 9.8 and can be remotely exploited without authentication.
Successful exploitation can allow an unauthenticated attacker with network access to compromise affected PeopleSoft environments, with potential impacts to confidentiality, integrity and availability.
Oracle later incorporated the fix into its June Critical Security Patch Update and strongly urged customers to apply the PeopleSoft updates.
BreachNews previously documented ShinyHunters-linked exploitation of CVE-2026-35273 against PeopleSoft environments, including organizations in the education sector.
The FBI has not publicly confirmed that CVE-2026-35273 was the specific vulnerability left unpatched in the FBIJobs.gov environment. ShinyHunters had also claimed it discovered an additional PeopleSoft vulnerability during its attacks, but that claim remains unverified.
FBI employee data was stolen
The consequences of the patch failure extended beyond access to a public recruitment website.
BreachNews later reported that FBI employee information was stolen during the ShinyHunters intrusion, substantially increasing the potential impact of the incident.
ShinyHunters claimed it obtained between 2 TB and 3 TB of information from the FBI environment and gained access beyond the recruitment platform. The FBI has not confirmed the group’s claimed data volume or the full extent of its alleged access.
Material obtained by journalists reportedly included information associated with thousands of FBI personnel. Reuters reported that the exposed information included counterintelligence job details, physical addresses associated with personnel involved in human intelligence operations and medical records. Journalists independently corroborated portions of the stolen material, although the complete dataset and ShinyHunters’ claimed 2 TB to 3 TB volume have not been verified.
The complete scope of the stolen data remains unresolved.
Accenture link adds third-party risk questions
The reported involvement of an Accenture contractor introduces another third-party security dimension to the incident.
Accenture is a major global professional services company that provides consulting, technology and managed services to government and enterprise customers.
The company has separately appeared in recent BreachNews coverage following an unrelated security claim. In July, BreachNews reported that Accenture was allegedly breached after a threat actor offered purported source code and cloud credentials for sale.
There is no evidence connecting that alleged Accenture breach to the FBIJobs.gov incident, and the circumstances described in the 2 cases are materially different.
In the FBI case, the new reporting concerns an individual contractor’s alleged failure to deploy a security update to a platform supporting the bureau. It does not establish that Accenture’s own corporate network was compromised or that attackers gained access through Accenture infrastructure.
The distinction is important because the FBI’s finding points to patch management and third-party administration as the security failure rather than a separate compromise of the contractor’s employer.
Finding resolves a major question in FBI investigation
The patch failure answers one of the biggest technical questions surrounding the breach, although several details remain unknown.
The FBI has not publicly identified the exact vulnerability exploited, disclosed when attackers first entered the environment or confirmed all systems ShinyHunters allegedly accessed.
The development also comes as international investigations into ShinyHunters continue. Jordan recently confirmed the arrest of a suspected ShinyHunters member as the FBI investigation expanded, following a separate arrest in the Netherlands.
The FBI has increasingly focused publicly on the group. Leatherman previously said ShinyHunters and alleged co-conspirators have compromised more than 140 organizations since 2025 and received at least $70 million through extortion.
For the FBIJobs.gov intrusion, however, the latest finding shifts part of the focus from the attackers to the security controls surrounding the affected system. What initially remained an open question about whether the FBI or a third party was the point of compromise now reportedly traces back to a security update that was available but was not installed.










