The FBI has removed an Accenture contractor after a data breach exposed sensitive personal information of thousands of bureau employees, two sources familiar with the matter told Reuters. The contractor was removed on Monday, October 5 after the FBI found that a security patch had not been properly installed on a platform managed by a third party. As per the report, the FBI breach comes weeks after Google warned about a hacking and extortion campaign linked to ShinyHunters targeting organisations that use PeopleSoft software.The FBI is still assessing the full impact of the breach, which exposed sensitive information including details of employees’ counterintelligence work, addresses of human intelligence operatives, and medical and psychiatric records, the report stated.
FBI data breach exposed sensitive employee information
According to the Reuters report, the stolen information included detailed descriptions of named employees’ counterintelligence jobs, street addresses of human intelligence operatives, and medical and psychiatric records of FBI workers. ShinyHunters has credited a vulnerability in PeopleSoft for helping it gain access to the system.FBI cyber chief Brett Leatherman confirmed that an unidentified contractor had failed to properly update the system. “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said in a statement to Reuters.“As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” he added.The FBI did not name the platform or the third-party company. However, two sources familiar with the matter told Reuters that the platform was Oracle’s PeopleSoft, a human resources system. The hacking group ShinyHunters has said it used a PeopleSoft weakness to break into the FBI’s job site last month.The two sources told Reuters that Accenture was the third-party organisation managing the platform.
Google warned about PeopleSoft hacking campaign
As stated above, the FBI breach comes after Google warned about a hacking and extortion campaign linked to ShinyHunters targeting organisations that use PeopleSoft software in June this year. The tech giant then raised the alarm about the campaign. Oracle issued a security alert on the same day, identifying a weakness in PeopleSoft and offering security fixes.Both companies urged organisations using PeopleSoft to “apply all Critical Patch Updates, Critical Security Patch Updates and Security Alerts without delay.”