The FBI reportedly removed an Accenture contractor over their role in a damaging data breach that exposed sensitive personal information belonging to thousands of bureau employees. The breach has rattled the agency as it continues to assess the full scope of the fallout, with some former bureau officials describing it as a serious blow to the organisation's operational security.
FBI data breach: What went wrong?
A senior FBI official confirmed to Reuters that the breach stemmed from a failure to apply a security patch to a third-party-managed platform. "To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization, after a contractor failed to implement a security patch explicitly issued to secure the platform," FBI cyber chief Brett Leatherman said in a statement to the news agency. He added that the bureau had "removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."
Identifying the platform and the contractor
While the FBI did not publicly name the platform or the third-party organisation involved, the report suggests that the affected system was Oracle's PeopleSoft, a widely used human resources platform. The hacking group ShinyHunters has claimed it exploited the platform to break into the FBI's job site last month.
The sources further identified Accenture as the third-party organisation managing the platform, though Reuters said it could not immediately identify the specific contractor involved or determine their current employment status. Oracle did not immediately respond to a request for comment, while Accenture said in a statement that it was "proud to support the mission of the FBI and will continue to do so," without addressing questions about the contractor or the alleged patching failure.
The breach has triggered significant concern within the FBI and the broader intelligence community, given the sensitivity of what was exposed. According to the report, the compromised information included detailed descriptions of named employees' counterintelligence roles, the street addresses of human intelligence operatives, and medical and psychiatric records belonging to bureau workers.
