WorkThe story, in brief

FBI removes contractor working with its PeopleSoft system after data breach, says report

FBI contractor removed after unpatched PeopleSoft left employee data exposed — first confirmation that a third-party implementation failure, not just a hacker, enabled the breach.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A concrete case of enterprise platform security failure landing on a federal agency: an Accenture contractor managing Oracle PeopleSoft didn't patch a known vulnerability, exposing FBI workforce data. For enterprise practitioners, it underscores the gap between vendor patches and actual deployment discipline — and the contractor accountability question.

The key facts

12 to know
  1. FBI Cyber Division confirmed breach resulted from 'security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch'

  2. Accenture was the third-party vendor (confirmed by Reuters sources, not FBI)

  3. Oracle PeopleSoft was the unpatched platform (previously only ShinyHunters claimed responsibility without naming the product)

  4. FBI has removed the contractor and 'taken all necessary steps to mitigate any further risk'

  5. Specific patch details, number of affected records, and timeline of the failure not disclosed

  6. ShinyHunters' original breach claim preceded this third-party accountability narrative

  7. Accenture contractor removed after failing to implement explicit security patch on PeopleSoft

  8. FBI Cyber Division confirmed: 'security failure of a platform managed by a third-party organization'

  9. Hacker group ShinyHunters had claimed responsibility for the breach last month

  10. First independent confirmation that Oracle PeopleSoft was the unpatched platform (not just ShinyHunters' claim)

  11. FBI took 'all necessary steps to both mitigate any further risk'—specific remediation scope not disclosed

  12. Reuters reporting via 'two sources familiar with the matter'—Accenture and PeopleSoft not named in official FBI statement

The story so far

Earlier coverage of this storyline

  1. Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risksCIO
  2. This story

Go to the source

CIOcio.com

Publisher excerpt: The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation over their role in a data breach that exposed personal details of FBI employees, Reuters reported Monday. This is the first time that anyone other than the hacker group Shinyhunters…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work