The ShinyHunters group managed to breach the FBI ’s recruitment system by exploiting a critical vulnerability in a platform (said to be Oracle PeopleSoft ) — and the cause was the failure to apply a patch that had already been issued. The FBI announced that it had fired the Accenture contractor responsible for managing the platform after it was discovered that the required security update had not been applied . The incident highlights once again how dangerous delay in applying patches can be, even in high-security organizations.

According to a report by The Hacker News, Brett Leatherman, assistant director of the FBI, said: "Our investigation has determined that the incident occurred as a result of a security failure on a platform operated by a third-party organization — after a contractor failed to apply a security patch that was issued specifically for the security of the platform." He added that the FBI has fired the contractor and taken all necessary measures to mitigate the risk and protect its personnel.
Although the FBI did not officially reveal the name of the third organization, Reuters reported that it was the Oracle PeopleSoft, which the ShinyHunters claimed to have exploited to breach the FBI's job portal in September 2026. Accenture, in a statement to Reuters, said it was "proud to support the FBI's mission and will continue to do so."
See also: ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day
ShinyHunters and CVE-2026-35273: The technical analysis of the attack
According to a report by Google subsidiary Mandiant , the ShinyHunters group — tracked as UNC6240 — exploited a workaround for the CVE-2026-35273 vulnerability by using a URL-encoding trick to bypass a Web Application Firewall (WAF) rule . This rule was designed to block the vulnerable PSEMHUB (Environment Management Hub) endpoint. The CVE-2026-35273 vulnerability affects Oracle PeopleSoft Enterprise PeopleTools and is rated CVSS 9.8 .
This is an unauthenticated remote code execution vulnerability over HTTP, meaning an attacker could execute commands on a vulnerable PeopleSoft server without needing valid credentials. PeopleSoft is widely used for human resources management, payroll, benefits, and recruiting — making it a particularly attractive target for data theft. Mandiant and Google Threat Intelligence described the campaign as a “mass exploit,” indicating automated scanning and exploitation of exposed PeopleSoft systems across multiple domains, including education.
The timeline of the incident is revealing: Between May 27 and June 9, 2026 , Google Threat Intelligence and Mandiant detected an exploit of CVE-2026-35273 by actors affiliated with ShinyHunters . On September 22 , the group claimed to have compromised the FBI ’s employment website and stolen information about current and former agency employees, as well as prospective employees. On October 5 , the FBI fired the Accenture contractor responsible for the platform.

ShinyHunters: What data was exposed and what was the impact?
The data allegedly exposed is highly sensitive. It reportedly includes personal information of thousands of FBI employees, Social Security Numbers,medical and psychiatric information, family details, addresses, job details, and intelligence-related information. The ShinyHunters group also claimed to have managed to migrate from the public employment website to AWS GovCloud managed by the FBI, exploiting a flaw in network segmentation.
See also: FBI calls on ShinyHunters members to surrender, after arrest of alleged leader
The ShinyHunters group has a long history of attacking large organizations for data theft and extortion. Its campaigns typically combine exploiting applications exposed online, stealing identity and human resources records, threatening to publish stolen data, and public announcements to pressure victims and attract media attention. It is worth noting that two members of the group have already been arrested, while the FBI has warned that more arrests are expected.
ShinyHunters: What organizations should do to protect
The incident highlights critical lessons for any organization that outsources platforms to manage sensitive data. First, the availability of a patch does not equal risk mitigation — it’s the implementation that counts. Second, third-party systems remain part of an organization’s attack surface, even if they are managed externally. Third, recruiting and HR platforms are high-value targets, containing identity documents, addresses, medical information, and sensitive role details.

For immediate protection, organizations using Oracle PeopleSoft or PeopleTools should identify each instance, including systems managed by contractors or hosted in cloud environments, and immediately apply the security update for CVE-2026-35273. Also, remove direct Internet exposure where not necessary by placing management interfaces behind VPNs or zero-trust gateways. For systems that were exposed without a patch, a full analysis of logs, web requests, process execution, outbound connections, and database access should be performed.
See also: EY breach: ShinyHunters claims supply-chain access to Jira/GitHub/Azure
The FBI and Accenture is a stark reminder that patch management is not just a technical obligation — it’s a matter of governance and accountability. Responsibility for applying security updates must be explicit, measurable, and independently verifiable, especially when an outside provider manages a system containing government or regulated data. The FBI’s investigation is ongoing, with the agency warning that more developments in the ShinyHunters case are expected.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
