The US Federal Bureau of Investigation (FBI) has removed an Accenture contractor following a data breach that exposed sensitive personal information. This information belongs to thousands of FBI employees, according to two sources familiar with the matter who spoke to Reuters.

The FBI confirmed that the incident involved a failure to properly update or patch a system managed by a third-party organisation. FBI Cyber Division chief Brett Leatherman said the contractor failed to implement a security patch that had been explicitly issued to protect the platform.

As a result of this incident, the FBI removed the contractor and has confirmed that steps have been taken to lessen further risk and protect its workforce.

em360tech image

FBI Data Breach Linked to Third-Party Platform

The FBI has not publicly identified the third-party organisation or the platform involved. However, sources familiar with the incident said that the affected system was Oracle's human resources platform PeopleSoft, an organisation managed by Accenture.

Reuters said the individual contractor involved could not be identified nor could they establish their current employment status.

Accenture reiterated that it is committed to supporting the FBI but did not respond directly to questions about the contractor or their reported failure to apply the security patch. Oracle also had not immediately responded to Reuters' request for comment.

Reportedly, the affected PeopleSoft platform was specifically connected to the FBI's job site, fbijobs.gov. The hacking group ShinyHunters has previously claimed that it exploited a vulnerability in PeopleSoft to gain access to the site.

This alleged compromise of the portal was first acknowledged by the FBI in September. At that time the organisation said a cybercriminal group had claimed to have accessed the site and obtained FBI employee personally identifiable information. Back then the bureau said it was investigating whether the breach originated with a third-party provider or within the FBI's own enterprise.

Sensitive FBI Employee Data Exposed

The breach exposed sensitive information belonging to thousands of FBI employees. This information reportedly included descriptions of named employees' counterintelligence roles, addresses associated with human intelligence operatives, and medical and psychiatric records, according to Reuters sources.

Oracle’s PeopleSoft platform had already come under scrutiny in June, when Google warned of a ShinyHunters-linked campaign targeting PeopleSoft users and Oracle released security updates addressing the software vulnerabilities.

One of the vulnerabilities addressed in Oracle's June 2026 Critical Patch Update, CVE-2026-35278, affected the Performance Monitor component of PeopleSoft Enterprise PT PeopleTools. The vulnerability could allow an unauthenticated attacker with network access to compromise the platform and potentially take control of it.

Reuters has not established whether or when the relevant security fixes were applied to the FBI's job portal. ShinyHunters has claimed that a PeopleSoft vulnerability was used in the intrusion.

FBI Continues Investigation

Aside from what sources have said, the FBI itself has not disclosed the full extent of the information accessed in the incident and continues to assess the full scope of the impact.

The development comes as US authorities pursue the wider ShinyHunters campaign. The FBI announced the arrest of an alleged group leader in September, while a key suspect was detained in Jordan last week, Reuters reported. Sources told the news agency that the suspect was cooperating with authorities.