The Federal Bureau of Investigation has removed an Accenture contractor following a damaging data breach that exposed sensitive personal information belonging to thousands of bureau employees, according to two sources familiar with the matter.
The FBI is continuing to assess the consequences of the breach, which former bureau officials have described as a serious setback for the organisation’s operational security. The incident involved a system managed by a third-party organisation and has exposed information extending beyond ordinary employee records.
FBI cyber chief Brett Leatherman said an unidentified contractor had failed to apply a security patch to the system for which they were responsible. “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said in a statement to Reuters. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”
The FBI did not identify the software platform or the third-party organisation involved. Two sources familiar with the matter told Reuters that the platform was Oracle’s PeopleSoft, a human resources system that the hacking group ShinyHunters has said it exploited to gain access to the FBI’s job site last month. The sources identified the third-party organisation as Accenture. Reuters was unable to identify the specific contractor or establish their current employment status.
Accenture said it remained committed to supporting the FBI. “We are proud to support the mission of the FBI and will continue to do so,” the company said, but it did not respond to questions about the contractor or the alleged failure to apply the patch. Oracle did not immediately respond to a request for comment.
The incident follows warnings earlier this year about attacks targeting organisations using PeopleSoft. In June, Google warned of a ShinyHunters-linked hacking and extortion campaign aimed at PeopleSoft users. Oracle issued a security alert on the same day identifying a vulnerability in the software and providing security fixes. Both companies urged organisations using PeopleSoft to apply their critical updates and security alerts without delay.
Reuters could not determine whether, or when, those responsible for securing the FBI’s job site applied the recommended fixes. ShinyHunters has said that a vulnerability in PeopleSoft helped facilitate its intrusion. Applying security patches is considered an important defence against cyberattacks, although updating large enterprise systems can be difficult and time-consuming.
The breach has exposed highly sensitive information within the FBI and the wider intelligence community. Compromised material reportedly includes detailed descriptions of named employees’ counterintelligence roles, street addresses of human intelligence operatives, and medical and psychiatric records belonging to bureau staff.
The investigation has continued as authorities seek to determine the full extent of the damage. Last week, a key ShinyHunters suspect was detained in Jordan. Sources told Reuters that the alleged hacker was cooperating, potentially providing information that could help the FBI determine the scope of the breach and limit its consequences.

