Skip to main content
Emerging ThreatsMalware & Ransomware

FBI Removes Accenture Contractor Over ShinyHunters Breach Patch Failure

Government office building exterior with subtle tech elements.

CVE-2026-35273 — the vulnerability Google-owned Mandiant says ShinyHunters exploited — lies at the center of a breach that exposed personal details of thousands of FBI employees.

How Mandiant says ShinyHunters bypassed protection

In a technical assessment cited by The Hacker News, Google-owned Mandiant attributed the intrusion technique to a URL-encoding trick used to defeat a web application firewall (WAF) rule. According to Mandiant, the bypass targeted a vulnerable Environment Management Hub endpoint identified as PSEMHUB and exploited a specific vulnerability cataloged as CVE-2026-35273. The report says the trick allowed an attacker to get around a WAF rule that was intended to block access to the endpoint.

FBI attributes the breach to a third‑party patch failure and removes contractor

The FBI has told staff that its internal review "has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform," Brett Leatherman, assistant director of the FBI's cyber division, was quoted as saying to the FBI. "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."

Those sentences capture the agency's direct attribution of the immediate cause: a contractor did not apply a patch that the FBI says had been explicitly issued to secure the platform. The bureau said it removed the contractor and undertook mitigation measures, though the FBI statement quoted in reporting did not name the contractor or describe the specific mitigation steps beyond that assurance.

Oracle PeopleSoft identified as the likely affected platform

While the FBI did not disclose the name of the third-party platform in its statement, Reuters reported that the platform is Oracle PeopleSoft, and the ShinyHunters group said it exploited that product to breach the FBI's job portal last month. The Hacker News reached out to both the FBI and Oracle for comment and said it would update the story if either replied.

Accenture, however, issued a brief public statement to Reuters: it said it was "proud to support the mission of the FBI and will continue to do so." The record in public reporting links an Accenture contractor to the removal action described by the FBI, but does not include further detail on contractual responsibility, oversight, or the timeline of the patch issuance and implementation.

Law enforcement actions and the status of the investigation

The breach has already produced arrests: reporting notes that two members of the ShinyHunters group have been arrested as part of the FBI's probe. The agency said it is "actively working with partners to obtain and execute more leads," and warned that additional arrests are likely to come. Those steps indicate an ongoing criminal investigation in parallel with the bureau's internal review of controls and third-party management.

What this means for security teams, procurement leaders, and affected employees

  • Security teams and technologists: The Mandiant assessment underscores how evasive encoding techniques can be used to circumvent WAF rules protecting specific endpoints — in this case, PSEMHUB — and that patching alone is necessary but not always sufficient if protections are not correctly tuned or implemented around vulnerable components.
  • Procurement leaders and enterprises that run PeopleSoft or similar third‑party platforms: The incident highlights the operational risk when third-party software or managed platforms require coordinated patching — and the consequences when a contractor responsible for implementing updates fails to act on an explicit security patch.
  • Affected employees and the public: The breach resulted in the theft of personal details for thousands of bureau employees; the FBI says it has taken steps to mitigate further risk and to protect its workforce, even as the criminal investigation continues.

The FBI's account ties the immediate failure to a contractor's missed patch, Mandiant's analysis explains the technical bypass used, and Reuters links the incident to Oracle PeopleSoft as the likely affected platform. Together those elements form a narrow but consequential chain: a known vulnerability, a reported failure to apply a patch, and an exploitation method designed to slip past existing WAF protections.

What remains clear from the reported facts is that the breach combined a specific software vulnerability (CVE-2026-35273), an operational lapse in patch implementation, and an exploitation technique tailored to evade a WAF rule aimed at PSEMHUB. The FBI has removed an Accenture contractor in response, made arrests in the criminal inquiry, and warned more arrests are likely as work to "obtain and execute more leads" continues.

Original story