Skip to content

Security2 publishers2 min readPublished

FBI traces ShinyHunters breach of employee data to a patch a contractor failed to apply

FBI said a contractor's failure to apply a security patch on a third-party platform let ShinyHunters steal personal details of thousands of bureau employees. The patch had already been issued, so the breach came down to one missed update on a platform the Bureau did not manage itself.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying FBI traces ShinyHunters breach of employee data to a patch a contractor failed to apply
Generated illustration

What happened

  • The FBI removed the contractor, who Reuters, citing two people familiar with the matter, reported was working for Accenture.
  • The Bureau withheld the platform's name; Reuters reported it is Oracle PeopleSoft, which ShinyHunters said it used to breach the FBI job portal last month.
  • Mandiant assesses that ShinyHunters exploits a bypass for CVE-2026-35273, using URL encoding to get past a WAF rule meant to block the vulnerable PSEMHUB endpoint.
  • Two ShinyHunters members have been arrested, and the FBI says more arrests are likely as it works leads with partners.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Unpatched PeopleSoft servers that depend on the WAF rule to block PSEMHUB are open to a technique Mandiant has already tied to an active group.
  • decision When a third party runs the platform and its staff skip a patch, the customer's employees lose their data, so the customer has to check the patch state of those systems itself.
  • precedent Agencies now have a public case of naming a contractor's missed patch as the cause and removing the individual, while the employing firm says it will stay on.

Brett Leatherman, assistant director of the FBI's cyber division, traced the failure to a single step. The incident "occurred as the result of a security failure of a platform managed by a third-party organization," he said, "after a contractor failed to implement a security patch explicitly issued to secure the platform." [3][4] He added: "As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce." [5]

By the Bureau's own account, the fix existed before the intrusion [4]. The flaw Mandiant links to the group, CVE-2026-35273, already has an identifier and a WAF rule written against it. The new part is the URL encoding that gets requests past that rule [8]. That leaves an unpatched PeopleSoft server exposed to the technique if the filter is its only protection on the PSEMHUB endpoint [12]. Mandiant's assessment, as reported, describes the group's method in general [8]. If the FBI's server was reached the same way, the filter was the control that got bypassed and the patch was the control that was missing [14].

The claims rest on different sources. Only the patch failure and the removal come from the FBI on the record [4][5]. Reuters supplied both Accenture's involvement and the PeopleSoft identification, and the Accenture link rests on two unnamed sources [2][6]. ShinyHunters itself claimed the job portal as its way in [7].

On this record, one person paid for the missed patch [1][5]. Accenture said it was "proud to support the mission of the FBI and will continue to do so." [9] Nothing in the reporting shows the firm losing the account [1][9].

The Bureau's case against the group is still producing arrests [10][11]. Arrests act on people. Mandiant's finding is about a filter configuration on PeopleSoft servers, and arrests leave that configuration as it was [13].

What to watch

  • Whether the FBI or Oracle names the patch and confirms CVE-2026-35273 as the route into the Bureau's PeopleSoft platform.
  • Any change to Accenture's FBI work beyond the removal of one contractor.
  • Further ShinyHunters arrests, and whether Mandiant reports the URL-encoding bypass against other PeopleSoft operators.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories