The FBI has removed an Accenture contractor over a damaging data breach that exposed sensitive personal details of thousands of bureau employees, according to a Reuters exclusive published Monday.
A senior FBI official told Reuters the breach resulted from a contractor’s failure to properly update — or patch — a platform they were responsible for. Two sources familiar with the matter told Reuters the platform was Oracle’s PeopleSoft human-resources software, which the hacking group ShinyHunters said last month it had exploited to break into the FBI’s job site.
FBI Cyber Division chief Brett Leatherman confirmed the contractor had been removed: “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform.”
The exposed information reportedly included detailed descriptions of named employees’ counterintelligence jobs, street addresses of human intelligence operatives, and medical and psychiatric records of bureau workers. Some former FBI officials have described the breach as a major blow to the bureau’s operational security.
Accenture said it was “proud to support the mission of the FBI and will continue to do so,” but did not answer Reuters’ questions about the contractor or the alleged patching failure. A key ShinyHunters suspect was detained in Jordan last week and is reportedly cooperating with authorities.
