Accenture
FBI removes Accenture contractor after ShinyHunters breach exposed thousands of staff records DICSON/Unsplash

A missed security patch on an Oracle PeopleSoft system managed by Accenture allowed the ShinyHunters hacking gang to break into the FBI's recruitment platform and steal sensitive personal data on thousands of bureau employees, prompting the US Federal Bureau of Investigation to remove the contractor from its role.

The news came after weeks of internal alarm inside the FBI, with former officials describing the intrusion as a serious blow to operational security.

To recall, ShinyHunters claimed in late September that it had broken into the FBI's jobs portal, FBIJobs.gov, and walked away with names, home addresses, Social Security numbers, job assignments and even medical and psychiatric records of staff.

How a Missed Patch Opened the Door to Shinyhunters

FBI cyber chief Brett Leatherman confirmed in a statement to Reuters that the incident stemmed from a 'security failure of a platform managed by a third‑party organisation' after a contractor failed to apply a patch explicitly issued to secure it.

'As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,' he said.

Reuters sources identified the vulnerable system as Oracle PeopleSoft, the human resources platform powering the bureau's recruitment site, and named Accenture as the third party responsible for managing it.

Oracle did not immediately respond to a request for comment, while Accenture said only that it was 'proud to support the mission of the FBI and will continue to do so', declining to address the contractor or the alleged patch failure.

For context, Google's Mandiant team flagged in June that ShinyHunters was running a hack‑and‑extort campaign targeting organisations using PeopleSoft, and Oracle issued a security alert the same day urging customers to apply critical patches without delay.

Swift patching is basic cyber hygiene, yet enterprise rollouts can be slow and messy, especially on systems serving large workforces. That gap between advisory and action is where this breach appears to have taken root.

What Was Stolen and Why It Matters

The breach has unsettled the FBI and wider intelligence community because the stolen files go beyond routine HR data. According to reporting, the trove includes detailed descriptions of named employees' counterintelligence roles, street addresses of human intelligence operatives, and medical and psychiatric records of bureau workers.

In practical terms, that means adversaries could map out who is working on China, Russia or drug cartels, and where some of those people live.

ShinyHunters told reporters the haul also covered background screening systems, MedLink employee health records and other internal services, and it circulated samples to journalists to bolster its claims.

IBTimes UK cannot independently verify every item in the hackers' dataset, so readers should treat those specific claims with caution, but the scale and sensitivity have been treated as credible by multiple outlets and former FBI personnel.

There is one piece of better news for the bureau. Last week, Reuters reported that a key ShinyHunters suspect was detained in Jordan and is cooperating with investigators, a development that could help the FBI narrow the scope of damage and identify what was actually exfiltrated.

The agency has warned that more arrests are likely as it pursues leads with international partners. Even so, the episode highlights a blunt reality in modern cyber defence: a single unpatched system, managed by a single contractor, can compromise the privacy and safety of thousands of public servants.

It also shows how a human resources portal became the weak point in one of the world's most security‑focused agencies.