FBI removes Accenture contractor following Oracle PeopleSoft data breach
The Federal Bureau of Investigation removed an Accenture contractor after an unpatched Oracle PeopleSoft vulnerability led to a breach exposing employee data.
FTMQ Security, written by our newsroom0 views

The Federal Bureau of Investigation has removed an Accenture contractor following a data breach that exposed personal details of FBI employees, according to CSO Online and CyberSecurityNews. The removal occurred after the contractor failed to apply an available security patch to the bureau's Oracle PeopleSoft installation. [1][2]
Rescana reported that the hacker group ShinyHunters exploited an unpatched vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273. CSO Online reported that the breach occurred as a result of a security failure on a platform managed by a third-party organization after the contractor failed to implement an explicit security patch. [1][3]
The incident marks the first time that the breach has been publicly linked to PeopleSoft by parties other than the hackers themselves, CSO Online reported. Oracle acquired PeopleSoft in 2005 for 10.3 billion dollars and has since integrated the software line under its ownership while continuing product development. [1][7]
In short
- The FBI removed an Accenture contractor after personal details of employees were exposed in a data breach.
- The breach resulted from a failure by the contractor to apply a security patch for Oracle PeopleSoft.
- Rescana linked the breach to the exploitation of Oracle PeopleSoft vulnerability CVE-2026-35273 by the group ShinyHunters.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]FBI removes contractor working with its PeopleSoft system after data breach, says reportCSO Online, 1d ago (the report this story comes from)
- [2]FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of EmployeesCyberSecurityNews, 1d ago
- [3]FBI Data Breach Analysis: ShinyHunters Exploit Unpatched Oracle PeopleSoft CVE-2026-35273 Due to Third-Party Patch FailureRescana, 1d ago
- [4]FBI Removes Accenture Contractor After Unpatched PeopleSoft System Exposes Employee DataCyber Press, 1d ago
- [5]Accenture Contractor Removed By FBI After Oracle PeopleSoft Breach Exposed Employee DataFree Press Journal, 1d ago
Background
- [6]Phoenix pay system on Wikipedia
- [7]PeopleSoft on Grokipedia
Our newsroom writes these reports with the help of software, from the 7 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
More in Top Stories
- Attackers hijack top level domains to obtain unauthorized Google security certificates7m ago
- Discord security bot Double Counter breached exposing user email addresses7m ago
- FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators7m ago
- MonsterCloud owner charged over secret ransomware payments8m ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records8m ago
- Fake AI Ad Portals Steal User Credentials and MFA Codes1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.