TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/FBI Now Blames a Contractor’s Missed Patch for the ShinyHunters Breach
News

FBI Now Blames a Contractor’s Missed Patch for the ShinyHunters Breach

The FBI says a contractor failed to apply a security patch on a platform it managed, 11 days after the bureau called the point of breach undetermined; Reuters’ sources name Oracle PeopleSoft and...

October 6, 2026 5 Min Read
27

The FBI says a contractor “failed to implement a security patch explicitly issued to secure the platform” behind the breach of its employees’ personal data, and that it has removed the contractor. Brett Leatherman, assistant director of the FBI’s Cyber Division, gave that account in a statement that Reuters reported on October 6 and SecurityWeek summarized. The bureau did not name the patch, the platform or the contractor.

Table Of Content

  • What the FBI and Reuters have said
  • From Undetermined to a Missed Patch in 11 Days
  • The PeopleSoft Dates
  • Why a Firewall Rule May Not Have Been Enough
  • What PeopleSoft Operators Should Check
  • What Is Still Unknown

The statement narrows the FBI’s account in 11 days. On September 25 an FBI spokesperson told The Register that “the point of breach is still undetermined.” ShinyHunters, which announced the hack on September 22, had told the same outlet it got in through an Oracle PeopleSoft zero-day. A patch the contractor failed to apply would mean the flaw was already fixed, so the two accounts cannot both be right about the same bug. The FBI has not said which patch it means.

What the FBI and Reuters have said

Reuters, citing two people familiar with the matter, reported that the affected system is Oracle’s PeopleSoft human resources platform and that the outside organization is Accenture, according to SecurityWeek’s summary. The FBI has not publicly named either. Accenture did not answer questions about the contractor or the alleged patching failure. It said it was “proud to support the mission of the FBI and will continue to do so.”

Leatherman’s statement said the incident “occurred as the result of a security failure of a platform managed by a third-party organization,” and that “the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.” A senior bureau official told Reuters the review so far points to a patch that the contractor responsible for the affected system had not applied. Reuters’ sources said the breach exposed personal information of thousands of bureau employees.

From Undetermined to a Missed Patch in 11 Days

ShinyHunters said it hacked the FBI to contest the bureau’s May 15 public service announcement about the group, which warned of harassment tactics and said ShinyHunters may falsely claim to hold compromising material. The group told The Register that it entered through another Oracle PeopleSoft zero-day in the FBIJobs.gov portal and then reached FBI-managed servers on AWS GovCloud. Samples that journalists and security researchers reviewed appeared to contain home addresses, phone numbers, Social Security numbers and emergency contact details, and the BBC saw samples of fitness-for-work medical examinations.

The FBI’s own early statements were more cautious. On September 25 it said it was “working closely with those third-party providers that support FBIJobs.gov,” and it left open “whether a third-party or the FBI’s enterprise” was the entry point. NPR reported on September 30 that the bureau was still investigating how the hackers got in. The October 6 statement answers it, at least for now: a platform managed by a third party, and a patch that was not applied.

None of the FBI statements reported so far gives a count of affected people. The BBC reported that the breach was first thought to affect the FBI’s 38,000 current employees, while the group now claims sensitive information on around 60,000 current and former staff. Reuters’ sources say thousands. None of those figures is a confirmed FBI number.

The PeopleSoft Dates

If the platform is PeopleSoft, as Reuters’ sources say, the public record for CVE-2026-35273 gives a timeline to read the FBI’s statement against. It is the PeopleSoft flaw ShinyHunters has been exploiting since May, but The Register described the group’s claim as “yet another Oracle PeopleSoft zero-day flaw,” so linking the FBI breach to CVE-2026-35273 is this article’s inference, not something either side has stated.

Date (2026) Event Source
May 27 to June 9 ShinyHunters, tracked by Google as UNC6240, exploits CVE-2026-35273 in PeopleSoft PeopleTools as a zero-day, mostly against higher education Google, June
June 10 Oracle publishes an out-of-band Security Alert covering PeopleTools 8.61 and 8.62 Oracle
June 12 CISA adds the flaw to its Known Exploited Vulnerabilities catalog with a June 15 due date and marks ransomware campaign use as Known CISA
September 22 ShinyHunters announces the FBI breach SecurityWeek
September 25 An FBI spokesperson says the point of breach is undetermined; Google reports renewed mass exploitation of the same flaw through a firewall bypass The Register, Google
October 6 The FBI says a contractor failed to apply a patch and removes the contractor Reuters, via SecurityWeek

Oracle’s alert came 104 days before ShinyHunters announced the FBI breach, and CISA’s June 15 due date came 99 days before it. Those counts show how long the alert had been public. They are not a finding about this contractor, because the FBI has not said which patch it means.

Why a Firewall Rule May Not Have Been Enough

Google’s September 25 post describes a renewed ShinyHunters campaign against the same flaw that “stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint.” The actor requested /%50SEMHUB/ in place of /PSEMHUB/, which URL-encodes one character. In Google’s words, “Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet.”

Google concluded that the group was “targeting organizations that implemented WAF rules but did not patch the vulnerability,” and said it had found web shells on “dozens of systems globally, spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government.” The post was published the same day the FBI confirmed the breach to The Register, and it does not mention the FBI. None of the statements reported so far says whether the contractor relied on a firewall rule instead of the patch.

What PeopleSoft Operators Should Check

Google’s quick guide is blunt: “WAF rules and path-based blocking are not a substitute for patching.” Its steps for anyone running PeopleSoft:

  • Apply the Oracle Security Alert patch for CVE-2026-35273, which Oracle lists as affecting PeopleTools 8.61 and 8.62.
  • Disable the Environment Management Hub service in multi-server configurations, or remove the PSEMHUB application in single-server ones, as Oracle’s guidance advises.
  • Search WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded variant such as /%50SEMHUB/, particularly POST requests to /hub.
  • Inspect the PSEMHUB.war directory for files that are not part of the product, including x.jsp, u.jsp, tunnel.jsp, tunnel.jspx and Ple64.exe.
  • Rotate credentials readable by the PeopleSoft application service account, including database connection strings and any cloud credentials reachable from the web tier.

For systems a contractor runs on your behalf, the FBI case suggests asking for the patch level itself, not a description of the compensating controls.

What Is Still Unknown

The FBI has not named the CVE, the platform or the contractor, and Accenture did not answer questions, so the PeopleSoft and Accenture details rest on Reuters’ two sources. The GovCloud claim is ShinyHunters’ own, and none of the FBI statements reported so far confirms it; Leatherman’s statement refers only to a platform managed by a third-party organization. The bureau also said it has “already worked with partners to arrest multiple subjects,” according to a statement The Register reported on October 5, and The Register noted that Dutch police had arrested a 24-year-old whom the FBI described as “one of the alleged leaders of ShinyHunters.”

We covered Oracle’s June alert for CVE-2026-35273 when it landed, and two recent posts tracked attackers exploiting flaws long after fixes shipped: Zimbra probing began eight days after its patch, and Rejetto HFS exploitation began 80 days after its fix.

Tags:

Data BreachesFBIOracle PeopleSoftShinyHuntersThird-Party RiskVulnerability Management

Share

Overhead view of an athletics starting block, with two angled foot plates on a slotted metal rail, lying on a red running track
Previous Post

How to Audit Python .pth Startup Hooks and Migrate to Python 3.15 .start Files

A glass-fronted green cabinet holding rows of old keys on numbered hooks, with several hooks empty
Next Post

The Root Key Rollover Turns DNSSEC Readiness Into a Check Only Some Resolvers Can Answer

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026