Threat Intelligence

Missed Patch at a Contractor Led to ShinyHunters Breach of FBI Job Portal, Staff Data Stolen

The Hacker News · 6 Oct 2026
Key Takeaway Check that your suppliers and managed service providers apply security patches promptly, write this expectation into contracts, and do not rely on a firewall rule alone to protect an unpatched system.

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor over an alleged role in a ShinyHunters breach that exposed personal details of thousands of bureau employees. According to Reuters, citing two sources, the FBI's review found the incident resulted from a security failure on a platform managed by a third party, after a contractor failed to apply a patch that had been explicitly issued to secure it. FBI cyber division assistant director Brett Leatherman said the bureau has removed the contractor and taken steps to reduce further risk and protect its workforce.

The FBI did not name the platform, but Reuters reported it was Oracle PeopleSoft. ShinyHunters said it exploited the software to breach the FBI's job portal last month. Mandiant, owned by Google, assesses that the group is exploiting a bypass for CVE-2026-35273. The technique uses a URL-encoding trick to get around a web application firewall rule meant to block the vulnerable Environment Management Hub (PSEMHUB) endpoint.

Accenture told Reuters it was proud to support the FBI's mission and will continue to do so. Two ShinyHunters members have been arrested, and the FBI says it is pursuing more leads and expects further arrests. The Hacker News has asked the FBI and Oracle for comment.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.