FBI Now Blames a Contractor’s Missed Patch for the ShinyHunters Breach
The FBI says a contractor failed to apply a security patch on a platform it managed, 11 days after the bureau called the point of breach undetermined; Reuters’ sources name Oracle PeopleSoft and...
The FBI says a contractor “failed to implement a security patch explicitly issued to secure the platform” behind the breach of its employees’ personal data, and that it has removed the contractor. Brett Leatherman, assistant director of the FBI’s Cyber Division, gave that account in a statement that Reuters reported on October 6 and SecurityWeek summarized. The bureau did not name the patch, the platform or the contractor.
Table Of Content
The statement narrows the FBI’s account in 11 days. On September 25 an FBI spokesperson told The Register that “the point of breach is still undetermined.” ShinyHunters, which announced the hack on September 22, had told the same outlet it got in through an Oracle PeopleSoft zero-day. A patch the contractor failed to apply would mean the flaw was already fixed, so the two accounts cannot both be right about the same bug. The FBI has not said which patch it means.
What the FBI and Reuters have said
Reuters, citing two people familiar with the matter, reported that the affected system is Oracle’s PeopleSoft human resources platform and that the outside organization is Accenture, according to SecurityWeek’s summary. The FBI has not publicly named either. Accenture did not answer questions about the contractor or the alleged patching failure. It said it was “proud to support the mission of the FBI and will continue to do so.”
Leatherman’s statement said the incident “occurred as the result of a security failure of a platform managed by a third-party organization,” and that “the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.” A senior bureau official told Reuters the review so far points to a patch that the contractor responsible for the affected system had not applied. Reuters’ sources said the breach exposed personal information of thousands of bureau employees.
From Undetermined to a Missed Patch in 11 Days
ShinyHunters said it hacked the FBI to contest the bureau’s May 15 public service announcement about the group, which warned of harassment tactics and said ShinyHunters may falsely claim to hold compromising material. The group told The Register that it entered through another Oracle PeopleSoft zero-day in the FBIJobs.gov portal and then reached FBI-managed servers on AWS GovCloud. Samples that journalists and security researchers reviewed appeared to contain home addresses, phone numbers, Social Security numbers and emergency contact details, and the BBC saw samples of fitness-for-work medical examinations.
The FBI’s own early statements were more cautious. On September 25 it said it was “working closely with those third-party providers that support FBIJobs.gov,” and it left open “whether a third-party or the FBI’s enterprise” was the entry point. NPR reported on September 30 that the bureau was still investigating how the hackers got in. The October 6 statement answers it, at least for now: a platform managed by a third party, and a patch that was not applied.
None of the FBI statements reported so far gives a count of affected people. The BBC reported that the breach was first thought to affect the FBI’s 38,000 current employees, while the group now claims sensitive information on around 60,000 current and former staff. Reuters’ sources say thousands. None of those figures is a confirmed FBI number.
The PeopleSoft Dates
If the platform is PeopleSoft, as Reuters’ sources say, the public record for CVE-2026-35273 gives a timeline to read the FBI’s statement against. It is the PeopleSoft flaw ShinyHunters has been exploiting since May, but The Register described the group’s claim as “yet another Oracle PeopleSoft zero-day flaw,” so linking the FBI breach to CVE-2026-35273 is this article’s inference, not something either side has stated.
| Date (2026) | Event | Source |
|---|---|---|
| May 27 to June 9 | ShinyHunters, tracked by Google as UNC6240, exploits CVE-2026-35273 in PeopleSoft PeopleTools as a zero-day, mostly against higher education | Google, June |
| June 10 | Oracle publishes an out-of-band Security Alert covering PeopleTools 8.61 and 8.62 | Oracle |
| June 12 | CISA adds the flaw to its Known Exploited Vulnerabilities catalog with a June 15 due date and marks ransomware campaign use as Known | CISA |
| September 22 | ShinyHunters announces the FBI breach | SecurityWeek |
| September 25 | An FBI spokesperson says the point of breach is undetermined; Google reports renewed mass exploitation of the same flaw through a firewall bypass | The Register, Google |
| October 6 | The FBI says a contractor failed to apply a patch and removes the contractor | Reuters, via SecurityWeek |
Oracle’s alert came 104 days before ShinyHunters announced the FBI breach, and CISA’s June 15 due date came 99 days before it. Those counts show how long the alert had been public. They are not a finding about this contractor, because the FBI has not said which patch it means.
Why a Firewall Rule May Not Have Been Enough
Google’s September 25 post describes a renewed ShinyHunters campaign against the same flaw that “stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint.” The actor requested /%50SEMHUB/ in place of /PSEMHUB/, which URL-encodes one character. In Google’s words, “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.”
Google concluded that the group was “targeting organizations that implemented WAF rules but did not patch the vulnerability,” and said it had found web shells on “dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government.” The post was published the same day the FBI confirmed the breach to The Register, and it does not mention the FBI. None of the statements reported so far says whether the contractor relied on a firewall rule instead of the patch.
What PeopleSoft Operators Should Check
Google’s quick guide is blunt: “WAF rules and path-based blocking are not a substitute for patching.” Its steps for anyone running PeopleSoft:
- Apply the Oracle Security Alert patch for CVE-2026-35273, which Oracle lists as affecting PeopleTools 8.61 and 8.62.
- Disable the Environment Management Hub service in multi-server configurations, or remove the PSEMHUB application in single-server ones, as Oracle’s guidance advises.
- Search WebLogic access logs for requests to
/PSEMHUB/and any percent-encoded variant such as/%50SEMHUB/, particularly POST requests to/hub. - Inspect the PSEMHUB.war directory for files that are not part of the product, including
x.jsp,u.jsp,tunnel.jsp,tunnel.jspxandPle64.exe. - Rotate credentials readable by the PeopleSoft application service account, including database connection strings and any cloud credentials reachable from the web tier.
For systems a contractor runs on your behalf, the FBI case suggests asking for the patch level itself, not a description of the compensating controls.
What Is Still Unknown
The FBI has not named the CVE, the platform or the contractor, and Accenture did not answer questions, so the PeopleSoft and Accenture details rest on Reuters’ two sources. The GovCloud claim is ShinyHunters’ own, and none of the FBI statements reported so far confirms it; Leatherman’s statement refers only to a platform managed by a third-party organization. The bureau also said it has “already worked with partners to arrest multiple subjects,” according to a statement The Register reported on October 5, and The Register noted that Dutch police had arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.”
We covered Oracle’s June alert for CVE-2026-35273 when it landed, and two recent posts tracked attackers exploiting flaws long after fixes shipped: Zimbra probing began eight days after its patch, and Rejetto HFS exploitation began 80 days after its fix.








No Comment! Be the first one.