A Known Security Flaw Was Left Unfixed. Hackers Took FBI Agents' Home Addresses.
The FBI says a contractor never installed a patch that was already written. Thousands of employees had personal files stolen anyway.
The FBI pulled an Accenture contractor off the job this week after a hacking crew stole personal records on thousands of bureau employees. The reason, according to the FBI's own cyber chief, was plain. A patch had been written to close a hole in a system a contractor was paid to watch. Nobody installed it.
Brett Leatherman, assistant director of the FBI's cyber division, told Reuters the break-in came from "a security failure of a platform managed by a third-party organization" after that contractor "failed to implement a security patch explicitly issued to secure the platform." The bureau then removed the contractor and said it had taken steps to limit further damage.
The FBI did not name the company or the software in that statement. Two people familiar with the matter told Reuters the software was Oracle PeopleSoft, the human-resources system behind the bureau's jobs site, and that Accenture was the firm running it. Accenture's public line was that it is "proud to support the mission of the FBI and will continue to do so." It did not answer questions about the contractor or the missed patch.
The hacking group, ShinyHunters, claimed the intrusion in late September. It said it got in through the jobs portal, FBIJobs.gov, then moved into other systems, including servers the bureau keeps on Amazon's government cloud. The group said it took two to three terabytes of files on agents, former employees, and job applicants. Reporters at 404 Media, Cybernews, and Reuters checked samples and matched some names, phone numbers, and addresses to real people. Reuters reported granular descriptions of named employees' counterintelligence jobs, street addresses of human-intelligence operatives, and medical and psychiatric records of bureau workers.
That is not a stolen-password problem. An agent whose home address and family details sit in a criminal file cannot fix it with a new credit card. Former bureau officials have called the intrusion a serious hit to operational security. Separately, investigators have arrested at least two people tied to ShinyHunters, including a suspect picked up in Jordan.
The software side is just as plain. Oracle had already issued a fix for a PeopleSoft flaw tracked as CVE-2026-35273. Researchers at Mandiant later said ShinyHunters was still getting through by a simple trick: changing one character in the web address so a firewall rule would not catch it. A fix on paper does nothing if the people paid to install it leave it on the shelf.
This is what happens when Washington hands the most sensitive personnel files in federal law enforcement to a stack of outside firms — a consulting giant, a software giant, and a cloud giant — and then treats a missed update like somebody else's problem. The bureau can fire one contractor. It cannot un-steal an agent's address.
Sources / More reading
The Hacker News, "FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach" (Oct. 6, 2026): https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html
Reuters, "Accenture contractor removed from FBI following damaging data breach, sources say" (Oct. 5, 2026): https://www.reuters.com/technology/accenture-contractor-removed-fbi-following-damaging-data-breach-sources-say-2026-10-06/
TechCrunch, "Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data" (Sept. 22, 2026): https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
BleepingComputer, "ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach" (Sept. 22, 2026): https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
CBS News, "Cybercriminal group claims it stole FBI personnel and applicant data" (Sept. 23, 2026): https://www.cbsnews.com/news/cybercriminal-group-fbi-data-shinyhunters/
Cybernews, "ShinyHunters claims FBI breach involving agents and job applicants" (Sept. 22, 2026): https://cybernews.com/news/shinyhunters-claims-fbi-systems-hack-sensitive-data-on-almost-all-fbi-agents/
The Hacker News, on the firewall bypass used against the PeopleSoft flaw: https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html
IBTimes UK, "FBI Removes Accenture Contractor Because a 'Security Failure' and Missing Patch Let ShinyHunters In" (Oct. 6, 2026): https://www.ibtimes.co.uk/fbi-removes-accenture-contractor-because-security-failure-missing-patch-let-shinyhunters-1823989