FBI blames contractor's missed patch for ShinyHunters breach
The FBI says a contractor failed to apply a patch for the Oracle PeopleSoft flaw CVE-2026-35273, leading to the ShinyHunters theft of employee data. The contractor was removed.
The FBI says the ShinyHunters theft of its employees' personal data traces to a contractor that failed to apply a security patch for the Oracle PeopleSoft flaw CVE-2026-35273. The bureau has removed the contractor from the project. The attribution comes from FBI cyber division assistant director Brett Leatherman, speaking to Reuters, as reported by SecurityWeek and The Hacker News. Both outlets name the contractor as Accenture; Accenture declined to answer specific questions.
What the FBI said
Leatherman's statement, verbatim: "To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform." He added that the FBI had "taken all necessary steps to both mitigate any further risk and protect our workforce."
The breach exposed the personal details of thousands of FBI employees, some of which was partially leaked to media outlets.
How the platform was hit
The underlying flaw is CVE-2026-35273 in Oracle PeopleSoft (NVD entry), which we covered when ShinyHunters first claimed the FBI data. According to Mandiant's analysis cited in the reporting, the attackers used a bypass for CVE-2026-35273 — URL-encoding to slip past web application firewall protections — against the PeopleSoft Environment Management Hub (PSEMHUB) endpoint. The FBI's framing is that the patch existed and was not applied; the WAF bypass is the technique that made an unpatched instance reachable.
Where this fits
- September 22, 2026 — ShinyHunters announced the breach.
- September 15 — an alleged group leader was arrested in the Netherlands.
- October 3 — a second alleged member, "Rey," was detained in Jordan and is reportedly cooperating with the FBI.
- October 6 — the FBI's public statement assigning cause to the missed patch.
What to do today
- If you run Oracle PeopleSoft, confirm the patch for CVE-2026-35273 is applied — the vendor fix, not just a WAF rule. This incident is a direct demonstration that a WAF-only mitigation was bypassed with URL-encoding.
- Audit the PSEMHUB endpoint exposure specifically, and restrict it to known management networks.
- Review patch accountability for managed/outsourced platforms. The failure here was organizational: a patch issued, a contractor responsible, and no verification that it landed. Confirm your MSP/contractor patch SLAs include evidence of application, not just a ticket closed.
Context
Attribution remains hedged where it should be: the FBI assigns the operational cause (a missed patch on a contractor-run platform) and Mandiant describes the technique, but two alleged ShinyHunters members are in custody as suspects, not convicted. The durable lesson for defenders is not about ShinyHunters — it is that a correctly-issued patch is worthless if no one verifies the third party applied it, and that a WAF in front of an unpatched service is a speed bump, not a fix.