Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, government] · confidence: medium · severity: critical · affected_sectors: [government] · au_impact: true

The FBI removed an Accenture contractor over their alleged role in a ShinyHunters breach that exposed personal details of thousands of bureau employees, according to Reuters citing the FBI's assistant director for cyber, Brett Leatherman. Leatherman said the incident stemmed from a security failure of a platform managed by a third party, after a contractor failed to implement a patch explicitly issued to secure it; the FBI removed the contractor and took mitigation steps. Reuters reported the platform as Oracle PeopleSoft, which ShinyHunters claimed to have exploited via the FBI's job portal last month. Mandiant assesses ShinyHunters used a URL-encoding trick to bypass a WAF rule protecting the vulnerable PSEMHUB endpoint (CVE-2026-35273). Two ShinyHunters members have been arrested, with the FBI warning more arrests are likely.

Attribute Detail
Sector Government
Date 2026-10-07
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-35273