
Accenture Contractor Removed After Bypassing CVE-2026-35273 Patch on Oracle PeopleSoft Exposed FBI Employee Data
FBI fired an Accenture contractor for missing the CVE-2026-35273 patch on Oracle PeopleSoft, enabling ShinyHunters access to thousands of employee records. Technical evidence points to a known WAF bypass; official statements emphasize third-party fault while procurement data shows recurring oversight gaps. Further arrests and federal-wide audits are probable.
The breach occurred when a URL-encoding bypass evaded the WAF rule protecting the PSEMHUB endpoint on Oracle PeopleSoft. Mandiant's assessment confirms the technique matched prior ShinyHunters activity against unpatched instances. FBI statements attribute the incident solely to the third-party platform operator yet omit any internal review of contractor oversight or prior patch deployment logs. Procurement records show Accenture holds multiple FBI IT support task orders; removal of one individual does not alter the broader pattern of deferred maintenance on critical HR systems. Cross-referencing court filings from earlier ShinyHunters arrests reveals repeated targeting of government job portals, suggesting reconnaissance rather than opportunistic activity. No public evidence links the stolen records to subsequent operations against FBI personnel. Oracle has issued no updated advisory on residual bypass vectors. Expect additional contractor terminations and internal audits of PeopleSoft instances across other federal agencies within 90 days.
FBI Cyber Division: At least two additional contractor terminations announced by end of Q4 2026 tied to unpatched PeopleSoft instances.
Sources (3)
- [1]Reuters FBI Accenture Report(https://www.reuters.com/world/us/fbi-removes-accenture-contractor-after-shinyhunters-breach-2026)
- [2]Mandiant ShinyHunters TTP Analysis(https://www.mandiant.com/resources/blog/shinyhunters-cve-2026-35273-bypass)
- [3]The Hacker News Original Coverage(https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html)