5 hrs ago
FBI Removes Accenture Contractor After Employee Data Breach
The FBI found that private information about thousands of its workers had been exposed.
The information included their jobs, addresses, and health records.
The FBI says a contractor did not install a security fix for the system.
The FBI removed the contractor and says it took steps to reduce further risk.
Sources told Reuters that Accenture managed the system and that it was Oracle PeopleSoft.
The FBI has not confirmed those details publicly.
A hacking group called ShinyHunters said it exploited a weakness in PeopleSoft.
The FBI is still working to understand how much harm the breach caused.
The FBI removed an unidentified Accenture contractor after a breach exposed sensitive information about thousands of bureau employees.
The FBI said the incident followed a failure to install a security patch issued to protect the platform.
Sources identified the affected system as Oracle PeopleSoft and Accenture as the platform manager; the FBI did not confirm those details.
Exposed information included employee job details, home addresses, and medical and psychiatric records.
Google and Oracle warned PeopleSoft users about security risks and urged them to apply fixes in June.
- Who
- The FBI removed an unidentified Accenture contractor; thousands of FBI employees had information exposed.
- What
- A data breach exposed sensitive employee information, and the FBI removed a contractor over an alleged failure to install a security patch.
- Where
- The breach affected an FBI employee job site; the FBI is based in the United States.
- When
- The removal was reported on October 5; the security warning and patch were issued in June.
- Why
- The FBI said the incident resulted from a security failure after a contractor failed to implement a patch issued to secure the platform.
Key facts
- Affected workforce
- Thousands of FBI employees
- Exposed information
- Job details, street addresses, and medical and psychiatric records
- Contractor
- An unidentified contractor was removed by the FBI
- Platform manager
- Sources identified Accenture; the FBI did not name the third-party organization
- System
- Sources identified Oracle PeopleSoft; the FBI did not name the platform
- Security warnings
- Google and Oracle issued warnings and urged users to apply security updates in June
- Reported hacking group
- ShinyHunters claimed it exploited a PeopleSoft vulnerability
Quotes
Brett Leatherman
FBI cyber chief
“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform. As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”
livemint.com




