FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
- ID
- 32195
- Status
- summarized
- Published
- 06 Oct 2026, 2:56 PM
- Fetched
- 06 Oct 2026, 5:23 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 06 Oct 2026, 5:24 PM
- Tags
- Audience
- developerssaas_founders
What happened
The FBI removed an Accenture contractor after a security failure on a third-party platform — reported by Reuters to be Oracle PeopleSoft — allowed ShinyHunters to steal personal details of thousands of FBI employees, according to assistant director Brett Leatherman. Mandiant assesses ShinyHunters bypassed a web application firewall rule protecting the vulnerable PSEMHUB endpoint for CVE-2026-35273 using a URL-encoding trick. Two ShinyHunters members have been arrested and the FBI says more are likely.
Why it matters
The concrete lesson is that the compensating control here was a WAF rule blocking a specific endpoint, and an attacker defeated it with URL encoding rather than a novel exploit — so if you rely on WAF path/endpoint rules instead of patching, treat those rules as temporary. The second detail worth acting on is contractual: the failure was attributed to a third-party-managed platform and a contractor who did not apply an explicitly issued patch, so patch SLAs and named accountability in vendor contracts are the thing to re-check, not your own stack. There is no Malaysian or Southeast Asian element in this text.
Discussion angle
Should a WAF rule ever be accepted as the fix for a known CVE, or only as a stopgap with an expiry date — and how would you write that into a managed-platform contract?