The US Federal Bureau of Investigation on Monday excluded a contractor working with Accenture after an internal review found that the contractor’s failure to apply a security update had led to a breach exposing sensitive personal data belonging to thousands of bureau employees. The data included detailed information about counter-intelligence operations carried out by named employees, as well as the home addresses of human intelligence sources and medical and psychological records of staff.
Bureau identifies breach damage and excludes contractor
The bureau is continuing to determine the breach’s consequences and the extent of the resulting damage, while former officials described the incident as a major blow to its operational security. A senior bureau official confirmed that the contractor, whose identity has not been disclosed, failed to update the system for which they were responsible as required.
Brett Lederman, head of the FBI’s cyber security division, said the review found that the incident resulted from a security flaw in a platform managed by an outside organisation after a contractor failed to install a security update issued specifically to protect the platform. He added that the bureau had excluded the contractor and taken all necessary steps to limit any further risks and protect its employees.
PeopleSoft platform identified and Accenture’s role clarified
The bureau did not name the platform or the outside organisation involved, but two sources familiar with the matter said the system targeted was Oracle’s PeopleSoft human resources platform and that the outside organisation was Accenture. The hacking group ShinyHunters had said it exploited the platform to breach the bureau’s jobs portal during September.
Accenture said in a statement that it was “proud to support the FBI’s mission and will continue to do so”. The company did not answer questions about the contractor concerned or allegations that the contractor had failed to implement the required security patch, while the contractor’s identity and current employment status remained unknown.
Google and Oracle warned of PeopleSoft vulnerability
Google had previously issued a warning in June about a hacking and extortion campaign linked to the ShinyHunters group that targeted organisations using PeopleSoft software. On the same day, Oracle issued a security alert announcing that it had discovered a vulnerability in the software and provided security fixes to address it.
Google and Oracle urged organisations using the targeted software to apply all critical fixes, critical security fixes and security alerts without delay. Quickly installing updates on software containing vulnerabilities is considered a basic measure for protecting networks and devices from hackers, but the process can be complex and arduous, particularly in the systems of large organisations serving huge numbers of users.
The contractor was excluded after Jordan detained a person last week suspected of belonging to the ShinyHunters group. Sources familiar with the matter said the suspect was “co-operating”, which could help the FBI determine the scale of the breach and understand the extent of the damage linked to it.
The group announced in September that it had breached the bureau’s jobs portal, claiming that it had obtained the names of former agents and job applicants, as well as home addresses, telephone numbers, spouses’ names and some medical information and other data.
The group sent a message to FBI Director Kash Patel and the bureau’s cyber security official, claiming that it possessed data on “almost” “all” employees and job applicants.