FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch led to a data breach exposing sensitive personal details of thousands of employees. According to Reuters, two sources identified Oracle’s PeopleSoft human resources platform as the affected system and Accenture as the service provider.

FBI cyber chief Brett Leatherman said the bureau’s review found that a contractor failed to install a patch issued to secure a platform managed by a third party. He said the FBI had removed the contractor and taken steps to reduce further risk and protect its workforce.

The FBI did not publicly name PeopleSoft or Accenture in its statement. Reuters could not establish the contractor’s identity or current employment status. Accenture said it would continue supporting the FBI but did not answer questions about the contractor or the alleged patching failure.

FBI Removes Accenture Contractor

The incident follows ShinyHunters’ claim that it breached the FBI’s job website through a PeopleSoft flaw in September. Earlier reporting described exposed names of staff in sensitive units and medical and psychiatric records. Such disclosures raise concerns beyond identity theft because they reveal information about employees working in sensitive roles.

However, Reuters previously said it could not confirm the group’s claimed PeopleSoft entry route. The contractor’s removal confirms a patching failure identified by the FBI, not every technical detail offered by the hackers about how they gained access.

Separate research provides important context. Cyber Security News previously covered CVE-2026-35273, a critical PeopleSoft flaw that allows attackers to run code without signing in. That report identified the Environment Management Hub component as the target. The available FBI statement does not identify a CVE or confirm that the specific vulnerability was exploited.

In September, Google’s Mandiant reported renewed PeopleSoft attacks against organizations that used web application firewall rules but had not installed Oracle’s update. Attackers adapted to those defenses, showing why temporary filters cannot replace a patch that fixes the underlying flaw.

For PeopleSoft administrators, the practical lesson is to apply vendor fixes promptly, verify installation, and check for suspicious access. Clear patching duties also matter when outside contractors manage sensitive employee systems.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees appeared first on Cyber Security News.