FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
The FBI has removed an Accenture contractor after a ShinyHunters-related breach allegedly exposed the personal details of thousands of bureau employees through a third-party platform failure. Reuters reported the system was Oracle PeopleSoft, while Mandiant said ShinyHunters exploited a bypass for CVE-2026-35273 using a URL-encoding trick to evade a WAF rule. #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #Accenture #FBI

Keypoints

  • The FBI removed an Accenture contractor tied to the breach investigation.
  • The incident reportedly exposed personal data of thousands of FBI employees.
  • Reuters identified the affected platform as Oracle PeopleSoft.
  • Mandiant said ShinyHunters used a URL-encoding trick to bypass a WAF rule for CVE-2026-35273.
  • The FBI said it is pursuing additional leads and more arrests may follow.

Read More: https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html