The FBI removed an Accenture contractor from work supporting the bureau after investigators concluded that a critical software update had not been installed before a damaging breach of its jobs website, according to two people familiar with the matter who spoke to Reuters. The sources identified the affected platform as Oracle PeopleSoft and said attackers exploited a known vulnerability. The FBI and Accenture have not publicly confirmed the personnel decision or that attribution, so those details remain source-based reporting rather than an official finding.
What is confirmed is that the FBI is investigating a compromise of fbijobs.gov and possible exposure of employee information. In a Sept. 23 statement, the bureau said it had not yet determined whether the initial breach occurred in its own environment or through a third party. It said investigators were working with providers that support the site to reduce risk. Accenture told Reuters that it remained proud to support the FBI but did not address the contractor or the alleged failure to patch.
A critical vulnerability with a public warning
The underlying flaw, tracked as CVE-2026-35273, affects Oracle PeopleSoft PeopleTools. Oracle issued an out-of-band security alert on June 10 and told customers to apply updates without delay. Google’s Mandiant and Threat Intelligence Group described it as a critical remote-code-execution vulnerability and said the ShinyHunters operation had exploited it as a previously unknown flaw before the patch became available. Google’s initial technical report documented observed activity from late May into early June, while Oracle’s advisory established the remediation path.
The risk did not end with the first disclosure. In a late-September update, Google said the same threat actor had resumed mass exploitation across multiple sectors. Investigators observed attempts to bypass web-application-firewall rules used as a temporary defense around the vulnerable PeopleSoft component. Google again advised organizations to install Oracle’s patch and remain on supported PeopleTools versions instead of relying only on perimeter filtering.
That sequence is important because it separates two security questions. The first is whether a vendor supplied a fix; Oracle did. The second is whether each operator identified every exposed instance, tested the update and deployed it before attackers returned. Reuters’ sources say that second process failed on the environment supporting the FBI site. The bureau has not publicly provided a technical timeline sufficient to independently verify that account.
Personal data raises the stakes
The group calling itself ShinyHunters claimed it obtained sensitive records connected to FBI personnel and job applicants. The FBI initially described the scope as alleged while it investigated. The Associated Press reported that the group claimed access to thousands of employee records and that the jobs portal had been compromised, while noting that the bureau had not established the point of entry. Reuters later reported, based on its sources, that exposed material included addresses, medical information and intelligence-related employment details.
Such information can create risks beyond conventional identity theft. Details about employment, family members, health or job functions may be useful for targeting, coercion or social engineering. The precise number of affected people and the full contents of the stolen data have not been independently established. That uncertainty is itself operationally significant: incident responders must protect potentially exposed individuals while forensic work determines what attackers actually accessed.
The episode also highlights how a public-facing recruiting system can become a route to highly sensitive data even when it is not part of a classified network. Government agencies depend on contractors and widely used commercial platforms for hiring, payroll and other administrative functions. Security therefore depends on the full chain of responsibility—software vendor, integrator, contractor and agency—not only on controls around intelligence systems.
The broader lesson for enterprise systems
Prompt patching sounds simple but can be difficult in large environments. Administrators must inventory affected systems, evaluate compatibility, schedule outages and confirm that mitigations work. Legacy human-resources platforms may also connect to databases and identity services, increasing the risk of disruption from rushed changes. Those constraints explain delay; they do not remove the exposure created when a critical, actively exploited flaw remains unpatched.
Contract language and staffing arrangements can further blur ownership. A sound program assigns a named party to monitor vendor alerts, another to approve emergency maintenance and a final party to verify deployment. Without that closed loop, a published fix may never reach the server that needs it most.
Google’s reporting adds another caution: compensating controls such as firewall rules may reduce risk temporarily, but attackers can adapt. Organizations using affected PeopleSoft versions should follow Oracle’s update guidance, review Google’s published indicators of compromise, search historical logs and treat unusual activity as a possible incident rather than assuming a blocked endpoint solved the problem.
For the FBI, the immediate priorities are determining the breach path, notifying affected people, limiting secondary exploitation and clarifying contractor accountability. For other institutions, the event is a warning that vulnerability management is not complete when an advisory is received. It is complete only when every exposed system is found, patched, tested and monitored—and when responsibility for each step is unmistakable.