FBI replaces contractor, thousands of employees’ data leaked.

Recently, the Federal Bureau of Investigation (FBI) in the United States experienced a data breach incident, where sensitive information of thousands of employees was leaked. An involved contractor has been replaced by the FBI, while the reasons behind the event and its impacts are still under investigation.

According to reports from Reuters, Brett Leatherman, a senior FBI official responsible for cybersecurity, confirmed that the investigation revealed the incident originated from a security vulnerability in a platform managed by a third-party organization. The contractor in charge of maintaining the system failed to install a security patch specifically designed to fix the vulnerability. The FBI stated that the contractor has been replaced, and measures are being taken to reduce further risks and protect employee information.

The FBI has not publicly disclosed the names of the platform or the third-party organization involved. However, two sources revealed that the attacked platform was Oracle’s PeopleSoft human resources system, and the third-party organization responsible for managing the platform was Accenture.

Accenture stated in a release that the company is “honored to support the work of the FBI” and will continue to provide relevant support but did not address questions regarding the involved contractor or the delayed installation of patches. Oracle has not responded to requests for comments.

In June of this year, Google issued a warning that hackers associated with the group “ShinyHunters” were exploiting vulnerabilities in PeopleSoft software to launch cyber attacks and ransom activities against organizations. Oracle subsequently issued a security alert on June 10, revealing a critical vulnerability CVE-2026-35273 in PeopleSoft and providing a fix.

Both Oracle and Google urged organizations using PeopleSoft to immediately install relevant key security updates and patches. It is currently unclear when or if the personnel responsible for the FBI’s system security implemented these security updates.

In September, ShinyHunters claimed to have infiltrated the FBI recruitment website FBIJobs.gov, stealing a large amount of employee and applicant data.

Reuters later analyzed a data sample of approximately 5,000 rows released by the hackers, which included some FBI employees’ names, contact information, work schedules, and records related to counterintelligence work targeting countries such as China, Russia, Iran, and Hezbollah, as well as sensitive positions involving data interception, electronic surveillance, and human intelligence (HUMINT).

The report stated that the authenticity of all data could not be verified, but some individuals and related information were independently verified.

Last Saturday (October 3), a man believed to be a key member of ShinyHunters was detained in Jordan. Sources revealed that the suspect is cooperating with the investigation and assisting the FBI and other law enforcement agencies in locating other members of the group. This development may help investigators further understand the extent of the invasion and the resulting losses.

Additionally, on September 15, the Dutch police arrested Pepijn van der Stap, a 24-year-old director of a cybersecurity company. He is suspected of having ties to ShinyHunters and being involved in the FBI recruitment website data breach.

ShinyHunters is a cybercriminal group primarily focused on data theft and ransom activities, and in recent years has targeted several large enterprises and organizations. Following the FBI data breach incident, the group’s website was taken offline at the end of September.