INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Accenture Contractor Misses Patch Causing ShinyHunters Job Site Data Breach
| 2026-10-06 06:56 CRITICAL HIGH DATA BREACH VULNERABILITY DISCLOSURE CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The FBI removed a contractor after a breach exposed sensitive information belonging to thousands of bureau employees, with the incident occurring on October 6, 2026. Saif al-Din Khader, suspected ShinyHunters member, was detained in Jordan and cooperating with the FBI and other authorities as early as October 3, 2026. The targeted sector is human resources, specifically Oracle PeopleSoft, a platform managed by Accenture, which was exploited to access sensitive information including medical records, street addresses of human intelligence operatives, and detailed descriptions of named employees' counterintelligence roles, affecting thousands of bureau employees. ShinyHunters used a critical vulnerability in the PeopleSoft Environment Management component, CVE-2026-35273, to bypass web application firewall rules and gain unauthorized access. The current status is that the FBI investigation continues with steps taken to limit further risk and protect its workforce after removing the contractor involved in the security failure.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Data Backup (ATT&CK mitigation for Defacement): Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups a
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fb•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
healthhealth
educationeducation
hospitalityhospitality
Incident Timeline
May 6
ShinyHunters switched to school-by-school extortion after compromising Instructure, the company that owns the Canvas online learning platform.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
While we don’t know for sure what this issue was, ShinyHunters switched to school-by-school extortion after
compromising Instructure
, the company that owns the Canvas online learning platform, in late April and after the initial pay-or-leak deadline passed on May 6.
tactic
Extortion
While we don’t know for sure what this issue was, ShinyHunters switched to school-by-school extortion after
compromising Instructure
, the company that owns the Canvas online learning platform, in late April and after the initial pay-or-leak deadline passed on May 6.
May 2026
Threat actors associated with ShinyHunters breached the FBI in May 2026, prompting Accenture to remove a contractor after discovering a patch failure.
Click on any entity below to view its context and source!
attribution
FBI
“Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report,” a spokesperson told
The Register
.
threat_actor
ShinyHunters
“Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report,” a spokesperson told
The Register
.
06, 2026
The FBI removed an Accenture contractor from a contract after the contractor's unpatched system was exploited by threat actors, leading to a breach by ShinyHunters.
June 9
Threat actors ShinyHunters exploited a zero-day vulnerability CVE-2026-35273 to breach higher-education institutions between May 27 and June 9.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
vulnerability
CVE-2026-35273
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
organisation
Mandiant
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
organisation
CVE-2026
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
general_metric
35273 CVE-2026
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
general_metric
27 May
Mandiant said ShinyHunters exploited CVE-2026-35273 as a zero-day between May 27 and June 9, initially focusing on higher-education institutions.
June 10
Oracle issued an out-of-band security alert on June 10, prompting the FBI to remove Accenture contractor after a patch failure led to ShinyHunters breach.
Click on any entity below to view its context and source!
organisation
Oracle
Oracle issued an
out-of-band security alert
on June 10.
2026/09/06
Threat actors, identified as ShinyHunters, exploited a vulnerability in Oracle PeopleSoft to breach the FBI's job portal.
Click on any entity below to view its context and source!
attribution
FBI
"
Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month.
organisation
Oracle PeopleSoft
"
Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month.
threat_actor
ShinyHunters
"
Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month.
September 15
Threat actors ShinyHunters breached a system, prompting the FBI to remove an Accenture contractor involved in its patching efforts on September 15.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Shortly after ShinyHunters announced the breach, law enforcement said it had arrested an alleged leader of the group in the Netherlands on September 15.
source_region
Netherlands
Shortly after ShinyHunters announced the breach, law enforcement said it had arrested an alleged leader of the group in the Netherlands on September 15.
September 22
Threat actors ShinyHunters claimed to have hacked FBI systems, leading to a breach of the agency's job application portal.
Click on any entity below to view its context and source!
attribution
FBI
The ShinyHunters cybercrime group announced on September 22 that it had
hacked FBI systems
.
FBI Investigation Continues
The development follows Hackread.com’s September 22
report
on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.
threat_actor
ShinyHunters
The ShinyHunters cybercrime group announced on September 22 that it had
hacked FBI systems
.
FBI Investigation Continues
The development follows Hackread.com’s September 22
report
on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.
tactic
Defacement
FBI Investigation Continues
The development follows Hackread.com’s September 22
report
on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.
attribution
FBI Investigation Continues
The development
FBI Investigation Continues
The development follows Hackread.com’s September 22
report
on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.
organisation
Hackread.com
FBI Investigation Continues
The development follows Hackread.com’s September 22
report
on ShinyHunters’ claimed compromise and defacement of the FBI’s job application portal.
October 3
The FBI removed an Accenture contractor from its contract after a patch failure was linked to the ShinyHunters breach.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The
arrest
of another alleged ShinyHunters leader, Saif al-Din Khader (aka Rey), came to light on October 3.
Reuters reported on October 3 that suspected ShinyHunters member Saif al-Din Khader was
detained in Jordan
and was cooperating with the FBI and other authorities.
attribution
FBI
Reuters reported on October 3 that suspected ShinyHunters member Saif al-Din Khader was
detained in Jordan
and was cooperating with the FBI and other authorities.
target_region
Jordan
Reuters reported on October 3 that suspected ShinyHunters member Saif al-Din Khader was
detained in Jordan
and was cooperating with the FBI and other authorities.
Oct 06, 2026
The FBI removed an Accenture contractor after a security patch failure allowed ShinyHunters to exploit CVE-2026-35273 and breach the Environment Management Hub, resulting in the theft of personal details from thousands of bureau employees.
Click on any entity below to view its context and source!
industry
Health
General Document Context
organisation
The Hacker News
The Hacker News has contacted both the FBI and Oracle for comment, and we will update the story if we hear back.
threat_actor
ShinyHunters
The development is the latest twist in the operational history of ShinyHunters, which has had
two of its members arrested
as the FBI continues its investigation into the breach.
According to a report from Google-owned Mandiant, ShinyHunters is assessed to be
exploiting
a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint.
The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the
theft of personal details
of thousands of bureau employees.
organisation
Google
According to a report from Google-owned Mandiant, ShinyHunters is assessed to be
exploiting
a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint.
organisation
Mandiant
According to a report from Google-owned Mandiant, ShinyHunters is assessed to be
exploiting
a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint.
organisation
CVE-2026
According to a report from Google-owned Mandiant, ShinyHunters is assessed to be
exploiting
a bypass for CVE-2026-35273 by using a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub (PSEMHUB) endpoint.
organisation
Reuters
That's according to a
report
from Reuters, citing two sources familiar with the matter.
2026/10/06
A contractor working for Accenture failed to apply a security patch, allowing ShinyHunters to exploit the PeopleSoft Environment Management vulnerability and breach the FBI's job portal.
Click on any entity below to view its context and source!
organisation
Reuters
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter.
Eduard Kovacs reports:
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter.
Two sources familiar with the case
told Reuters
that the contractor worked for Accenture.
threat_actor
ShinyHunters
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach.
ShinyHunters
had previously claimed it exploited PeopleSoft to break into the FBI’s job site, and Google recently
warned
that the threat actor had been targeting vulnerable PeopleSoft instances to steal data.
The attack allegedly aimed to pressure the FBI to correct or remove a report the agency published in May to warn organizations about ShinyHunters attacks.
ShinyHunters Claims PeopleSoft Flaw Enabled Access
ShinyHunters previously claimed it used a
PeopleSoft vulnerability
to access the FBI’s job portal.
'We refuted the misinformation disseminated by the FBI'
According to a spokesperson for ShinyHunters, the FBI hack isn’t about the money, and the crew did not demand a multimillion-dollar extortion payment to not leak the agents’ personal details.
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'.
On Friday, the FBI confirmed the breach to
The Register
, after earlier in the week saying the bureau was investigating ShinyHunters’ claims.
The FBI bulletin, published soon after the group breached ed-tech giant
Instructure's Canvas platform
and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff,
said
ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”
It also puts a huge target on the crew, and we’d bet that the FBI, already gunning to arrest ShinyHunters members, is now doubling down on those efforts.
According to ShinyHunters, the PeopleSoft preauth vulnerability that they exploited in the FBI attack still doesn’t have a patch.
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach.
ShinyHunters seemed
defiant
and urged victims to continue negotiating, threatening to leak their data unless they paid up.
At the time of writing, ShinyHunters’ website is still live, but a post urging organizations to pay up has been removed.
FBI Removes Accenture Contractor Over ShinyHunters Job Site Data Breach.
According to
Mandiant
, ShinyHunters used URL encoding to bypass web application firewall (WAF) rules that blocked access to the vulnerable
/PSEMHUB/
endpoint.
“It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told us.
They said it’s due to ShinyHunters’ “unique and exceptional reputation along with over five years of history in the space…We are in a unique position and due to our vast capabilities and resources, victims are more likely to resolve the situation quickly and cheaper with us instead of going down the full disclosure route.”
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to
millions
of
cancer patients
,
university
and
K-12 students
, and
Carnival cruisers
, wanted to preserve their reputation and keep their “business” afloat.
Meanwhile, that PeopleSoft 0day
The ed-tech company ultimately “reached an agreement” with ShinyHunters, which is corporate-speak for they paid the extortion demand.
ShinyHunters contends this is all false.
ShinyHunters said it believes that “future corporate partners we engage with for payment will review this documentation, reinforcing our reputation as serious, results-driven professionals focused solely on transaction and resolution.”
The spokesperson said they and others in the crew started off as
GnosticPlayers
before rebranding as ShinyHunters in 2020, and that they have since seen the “majority” of GnosticPlayers members arrested.
ShinyHunters claims that they “don't attack human beings.
organisation
Google
ShinyHunters
had previously claimed it exploited PeopleSoft to break into the FBI’s job site, and Google recently
warned
that the threat actor had been targeting vulnerable PeopleSoft instances to steal data.
organisation
the PeopleSoft Environment Management
Mandiant has separately documented the group’s exploitation of
CVE-2026-35273
, a critical vulnerability in the PeopleSoft Environment Management component, but it has not publicly connected its observations to the FBI breach.
organisation
Cyber Division
Brett Leatherman, assistant director of the FBI’s Cyber Division, said the incident resulted from a security failure involving a platform managed by a third-party organization.
organisation
PeopleSoft
ShinyHunters Claims PeopleSoft Flaw Enabled Access
ShinyHunters previously claimed it used a
PeopleSoft vulnerability
to access the FBI’s job portal.
Meanwhile, that PeopleSoft 0day
The ed-tech company ultimately “reached an agreement” with ShinyHunters, which is corporate-speak for they paid the extortion demand.
According to Reuters’ sources, the system in question is Oracle’s PeopleSoft human resources platform, and the outside organization is Accenture.
organisation
Oracle PeopleSoft
Reuters sources identified the software as Oracle PeopleSoft, a human resources platform, and the third-party provider as Accenture.
organisation
GnosticPlayers
The spokesperson said they and others in the crew started off as
GnosticPlayers
before rebranding as ShinyHunters in 2020, and that they have since seen the “majority” of GnosticPlayers members arrested.
organisation
Oracle’s
According to Reuters’ sources, the system in question is Oracle’s PeopleSoft human resources platform, and the outside organization is Accenture.
organisation
WAF
A WAF checking for the literal
/PSEMHUB/
path could treat the encoded request as different, while PeopleSoft decoded it and passed the request to the vulnerable application.
organisation
Oracle
Oracle hasn’t responded to
The Register
’s questions about the zero-day, or any plans for a patch.
organisation
The Register
’s
Oracle hasn’t responded to
The Register
’s questions about the zero-day, or any plans for a patch.
organisation
PII
The compromised portal displayed a page stating that the site had been seized, accompanied by claims involving personally identifiable information (PII) and protected health information (PHI).
organisation
PHI
The compromised portal displayed a page stating that the site had been seized, accompanied by claims involving personally identifiable information (PII) and protected health information (PHI).
organisation
Ransomware
Ransomware and other disruptive attacks are “substantially worse and costly,” they said.
organisation
Social Security
Sample files reviewed by journalists and security researchers appear to contain agents’ home addresses, phone numbers, email addresses, Social Security numbers, job titles, assigned field office, and emergency contact information.
organisation
Canvas
Think of the children
We also questioned how they justify doing what they do in this “business” - breaking into IT systems, stealing data, extorting victims - considering the personal toll it takes on people, especially when the stolen files contain sensitive information about children as they did in the Canvas intrusion.
organisation
Advanced Placement
They injected a ransom message into about 330 Canvas school login portals, causing Instructure to
take the platform offline
for a day - during final exams and Advanced Placement testing for many.
organisation
Alliance Risk
Alliance Risk CEO David Vainer previously told
The Register
he estimates the figure sits somewhere between $5 million and $30 million.
organisation
The Register
Alliance Risk CEO David Vainer previously told
The Register
he estimates the figure sits somewhere between $5 million and $30 million.
financial
$5 figure
Alliance Risk CEO David Vainer previously told
The Register
he estimates the figure sits somewhere between $5 million and $30 million.
Tactical Metrics
Metrics
financial
5,000,000
Figure
Click for context!
Alliance Risk CEO David Vainer previously told
The Register
he estimates the figure sits somewhere between $5 million and $30 million.
Intelligence Sources
The Register - Cybercrime
2026-09-25
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
The Register - Cybercrime
HackRead
2026-10-06
Data Breaches
2026-10-06
SecurityWeek
2026-10-06
The Hacker News
2026-10-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:04
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
Oracle PeopleSoft
entity
11x
timeline
Temporal Reference
Oct 06, 2026
date
8x
attribution
Attributing Entity
FBI
authority
4x
tactic
Cyber Operation Type
Data Breach
tactic
2x
source region
Origin Country
Netherlands
country
2x
target region
Target Country
United States
country
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
ShinyHunters
actor
vulnerability
Exploited CVE
CVE-2026-35273
cve
industry
Targeted Sector
Health
sector
general metric
Cve-2026
35,273
cve-2026
general metric
May
27
may
general metric
School Login
330
school login
financial
Figure
5,000,000
figure
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.