FBI Ends Accenture Contract Over Unpatched HR Platform Breach
The FBI's own account places the breach in a vendor's patch process rather than in its own systems, and the contractor it cut is identified only through Reuters' sourcing, not by the bureau.
Reporting from 1 source: GIGAZINE.
The FBI terminated its contract with a contractor after determining that a September 2026 leak of employee personal information happened because a security patch for a third-party human resources management platform was not applied. The cybercriminal group ShinyHunters stole data belonging to thousands of FBI employees. The FBI did not name the contractor or platform; Reuters, citing people familiar with the matter, identified them as Accenture and Oracle's PeopleSoft. Accenture declined to comment on the patch or contract status.
The patch in question had been explicitly distributed for the platform before the September 2026 theft, according to the FBI's account. The bureau said it terminated the contract and took measures to reduce risk and protect employees. Accenture did not answer whether the patch was applied or whether the contract still stands, and gave a statement that it is proud to support the FBI's mission and will continue to do so.
The attackers were ShinyHunters, the group believed to be pressuring the FBI over a report it had published. The bureau withheld the contractor and platform names; the Reuters identification of Accenture and PeopleSoft rests on unnamed sources.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.