Skip to content
Brief Security & Trust ·

FBI says contractor missed a patch before staff data breach; review ongoing

Reuters' sources name Oracle's PeopleSoft HR system and Accenture; the FBI's statement names neither.

In brief
  • The FBI says its review so far points to a contractor that skipped a security patch. Reuters' sources name Accenture and PeopleSoft.
  • The FBI has not tied the breach to ShinyHunters. The group's claims are unconfirmed.

Reuters reported on Tuesday that the FBI cut ties with a contractor. Two people familiar with the matter said a breach exposed personal details of thousands of staff. FBI cyber chief Brett Leatherman said the review so far shows a third-party platform was breached after a contractor skipped a security patch. The FBI did not name Accenture or say which party missed the patch. Reuters' sources named Accenture and Oracle's PeopleSoft HR platform.

The FBI has not said ShinyHunters did this or confirmed its claims. The group said on September 22 that it hacked the FBI's jobs site. It claimed data on all employees, a bigger number than Reuters' thousands. It had earlier claimed it used PeopleSoft, and Google recently warned the group had been targeting vulnerable PeopleSoft systems. Accenture answered no questions on the alleged missed patch, saying only it is proud to support the FBI. Still unknown: when the patch was issued, how long it was missing, and what data was taken.

Analysis: outsourcing operations does not outsource accountability. A patch is an update that closes a known flaw. Until it is installed, attackers can use that flaw against any system they can reach online. Buyers can ask who owns patching, how it is proven, and what the contract says about notice and liability.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: SecurityWeek.