FBI Fires Accenture Contractor Following Security Patch Failure
The FBI terminated an Accenture contractor after a failure to apply a critical Oracle PeopleSoft security patch led to a data breach of its job site.
By Muhamed Porić
October 10, 2026 at 8:11 PM

The FBI has terminated an Accenture contractor following a data breach of its job site. Officials attribute the decision to the contractor's failure to apply a security patch to an enterprise software platform.
The breach exposed internal data after the failure to update Oracle's PeopleSoft platform, a system used for human resources and applicant management. The hacking group ShinyHunters claimed responsibility for the intrusion, stating they exploited the vulnerability to access the bureau's recruitment portal.
"To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization. This happened after a contractor failed to implement a security patch explicitly issued to secure the platform," said Brett Leatherman, FBI cyber chief, in a statement.
The Mechanics of the Vulnerability
The security failure centered on the omission of a Critical Patch Update for the PeopleSoft platform. Oracle issued this security alert in June, following warnings from Google regarding a campaign linked to ShinyHunters that targeted known vulnerabilities in enterprise software.
In enterprise infrastructure, these patches close entry points that malicious actors use to bypass authentication protocols. By failing to implement the update, the contractor left the FBI's job site exposed to automated exploitation tools that groups use to identify unpatched systems across the public sector.
Accountability in Third-Party Management
For federal agencies, the reliance on third-party contractors creates a security perimeter where accountability is divided between the government entity and the private service provider. The FBI's decision to remove the contractor shows the pressure on agencies to enforce compliance with vendor security requirements, as cyber-extortion groups focus their efforts on the supply chains and administrative portals of government institutions.
The incident highlights the risks in maintaining software like PeopleSoft, which requires consistent, rapid patching to mitigate the threat of credential harvesting and unauthorized access. As the investigation into the data exposure continues, the FBI is evaluating its third-party risk management protocols to prevent similar lapses.
Muhamed Porić
Founder and Editor of Embers.
Newsletter
Get Embers in your inbox
The stories that actually moved something, delivered when there's something worth sending, not daily filler.