October 5, 2026 · Personnel, Competence & Administrative Failure · Personnel action
Confirmed

FBI Cuts Ties With Accenture Contractor After Breach Exposes Employee Data

Reuters reported late October 5, 2026 that the FBI removed an Accenture contractor after a breach, claimed by the hacking group ShinyHunters, exposed data on potentially thousands of bureau employees, including home addresses, phone numbers, spouses' information, and details about employees' intelligence and surveillance roles and private medical information. FBI cybersecurity chief Brett Leatherman said the incident resulted from "a security failure of a platform managed by a third-party organization," adding that "a contractor failed to implement a security patch explicitly issued to secure the platform." Accenture handles patch management for the FBI's Oracle PeopleSoft system; Oracle had issued the relevant patch before the breach occurred.

Leatherman said the FBI "has removed the contractor and taken all necessary steps" to limit further risk, though he did not explain why the patch went unapplied. Accenture said it is "proud to support the mission of the FBI." Researchers warned the data could help foreign intelligence services identify employees on sensitive investigations; ShinyHunters said it would not publish the data but did not say it had deleted it. Dutch police separately announced the arrest of an alleged ShinyHunters leader.
← Back to the ledger