The FBI has removed an Accenture contractor after determining that failing to install a security patch contributed to the recent breach that exposed highly sensitive information about bureau employees, Reuters said.
The unidentified contractor was responsible for maintaining a third-party platform supporting the FBI. According to FBI Cyber Division chief Brett Leatherman, the contractor failed to implement a security patch that had been specifically issued to protect the system.
Sources familiar with the investigation identified the affected software as Oracle PeopleSoft, an enterprise platform used for human resources and other organizational functions. They also identified Accenture as the third-party organization managing the platform.
The incident is connected to the recent compromise of FBIJobs.gov claimed by the ShinyHunters hacking group. The FBI initially said it was investigating whether the intrusion originated within its own environment or through a third-party provider.
ShinyHunters has said it exploited a PeopleSoft vulnerability to gain access. The group claimed to have stolen a large collection of information involving current and former FBI personnel, although the full amount of data claimed by the hackers has not been independently confirmed.
The information exposed in the incident is particularly sensitive. Reporting on samples of the stolen data found detailed descriptions of employees’ counterintelligence work, home addresses associated with human intelligence operatives, and medical and psychiatric information.
Oracle had released security fixes for a PeopleSoft vulnerability in June after attacks targeting organizations running the software were discovered. Customers were urged to install critical security updates without delay.
The FBI has not disclosed exactly when the vulnerable system should have been updated or how long it remained exposed. Accenture said it remains proud to support the FBI’s mission but did not answer questions about the contractor or the alleged failure to apply the patch.
The bureau says it has removed the contractor and taken additional measures to reduce further risks and protect employees. Investigators are still assessing the consequences of the breach and determining the full extent of the information compromised.