FBI Removes Accenture Contractor After Missed Patch Led to Employee Data Breach
The FBI has removed a contractor working for Accenture after investigators found a required security patch was not applied on a third-party platform, exposing personal data for thousands of employees in a breach claimed by ShinyHunters, according to Reuters and Nextgov/FCW.
The FBI has removed a contractor working for Accenture after finding that a security patch meant to protect a third-party platform was never put in place, opening the way for a breach that exposed personal information belonging to thousands of bureau employees, according to Reuters and Nextgov/FCW.
Reuters reported that the contractor was removed on Monday, citing two people familiar with the matter. In a statement, FBI cyber chief Brett Leatherman said the bureau’s review found the intrusion stemmed from a security failure on a platform run by an outside organization, after a contractor failed to apply a patch that had been issued specifically to secure it. He said the contractor was removed and that the bureau moved to limit further risk and protect its workforce, according to both reports.
What the intruders reached
The hacking group ShinyHunters claimed responsibility for the intrusion last month and said it used a weakness in Oracle’s PeopleSoft software to reach the FBI’s jobs site, according to Reuters. The FBI did not publicly name the platform or the company involved; the two Reuters sources identified them as PeopleSoft and Accenture. Nextgov/FCW reported that Accenture handles software patch management and custom code work at the bureau, and that Oracle supplied the fixes that were not integrated, citing a person with knowledge of the matter.
The material taken was unusually sensitive. Nextgov/FCW reported that it included home addresses, phone numbers, details about spouses, information on intelligence and surveillance assignments, and private medical records. Reuters described granular descriptions of employees’ counterintelligence work, street addresses tied to human intelligence personnel, and medical and psychiatric files among the exposed records.
Warnings that came earlier
The missed fix was not an obscure one. Reuters reported that in June, Google warned of a ShinyHunters-linked campaign aimed at organizations running PeopleSoft, and Oracle issued a security alert with fixes the same day, urging customers to apply them without delay. Nextgov/FCW noted that Google’s Mandiant unit has since found the group again exploiting the same PeopleSoft weakness at scale.
Accenture did not address the contractor or the patch in its response. The company said it was “proud to support the mission of the FBI” and would continue to do so, according to Reuters. Oracle did not immediately reply to a request for comment, Reuters reported.
Questions remain open. Nextgov/FCW reported that the bureau has not explained why the patch was missed or how closely the contractor’s work was supervised. Authorities have also been arresting suspected group members: Dutch police announced an alleged leader’s arrest last week, and Reuters reported Saturday that another suspect was detained in Jordan and was assisting investigators, according to Nextgov/FCW.
Reporting based on coverage by Nextgov/FCW and Reuters.