FBI Removes Accenture Contractor After Missed Oracle PeopleSoft Patch Enabled ShinyHunters Data Breach
FBI cyber chief
The FBI's blame of a missed vendor patch shifts scrutiny from the intrusion to contractor oversight across federal PeopleSoft deployments. A fix had been public since June, so this was a patch-governance failure, not an unknown flaw, which undercuts ShinyHunters' zero-day claim. Accenture handles patching at the bureau, leaving open how the FBI verified work on systems holding intelligence-role and medical records. The contractor and platform identifications rest on one anonymous-source chain through Reuters, so they warrant caution. Removing the contractor does not reverse the exposure, and recovery of the data is unconfirmed. The patch lapse may be only the stated cause, with contractor fault emphasized to deflect from FBI oversight and further weaknesses undisclosed. Other agencies running PeopleSoft should audit their own patch governance independently.
4 sources
- FBI removes Accenture contractor after missed security patch led to breach -
Nextgov/FCW - FBI Drops Accenture Contractor After Sensitive Data Breach -
Security Affairs - FBI data breach: Accenture contractor removed over missed patch -
Cybernews - FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach -
The Hacker News