Reuters reported on Tuesday that the FBI cut ties with a contractor. Two people familiar with the matter said a breach exposed personal details of thousands of staff. FBI cyber chief Brett Leatherman said the review so far shows a third-party platform was breached after a contractor skipped a security patch. The FBI did not name Accenture or say which party missed the patch. Reuters' sources named Accenture and Oracle's PeopleSoft HR platform.
The FBI has not said ShinyHunters did this or confirmed its claims. The group said on September 22 that it hacked the FBI's jobs site. It claimed data on all employees, a bigger number than Reuters' thousands. It had earlier claimed it used PeopleSoft, and Google recently warned the group had been targeting vulnerable PeopleSoft systems. Accenture answered no questions on the alleged missed patch, saying only it is proud to support the FBI. Still unknown: when the patch was issued, how long it was missing, and what data was taken.
Analysis: outsourcing operations does not outsource accountability. A patch is an update that closes a known flaw. Until it is installed, attackers can use that flaw against any system they can reach online. Buyers can ask who owns patching, how it is proven, and what the contract says about notice and liability.