FBI removed an Accenture contractor over a missed patch. Oracle issued it in June.
The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a data breach that exposed personal details of thousands of bureau employees, Reuters reported, citing sources.
FBI cyber chief Brett Leatherman said the breach came "after a contractor failed to implement a security patch explicitly issued to secure the platform." His statement does not name Accenture; Reuters' sources did.
The platform was Oracle's PeopleSoft HR software, which the hacking group ShinyHunters said it used to get into the FBI's job site in September. Google raised an alert in June and Oracle issued fixes the same month, Reuters reported. Exposed data included staff medical records.
Accenture said it was "proud to support the mission of the FBI and will continue to do so" and did not answer questions about the contractor or the patch. Oracle did not immediately respond.
Oracle's fixes existed from June and the break-in came in September. The statements do not say who was responsible for applying them, what deadline the contract set, or whether a delay was approved.
Does your support contract name who applies a patch, and by when?
Sources
Our file on Accenture
- 4 Oct
Accenture spent $923 million mostly on severance. Its headcount still rose to 814,000.
- 21 Sept
Anthropic let Accenture safety-test its AI from inside. Both expect to invest $1 billion.
For your next steering committee
- 1Ask which exit clauses your largest software and services contracts carry, and when each can be used.
- 2Ask what leaving would cost, in money and in months.
- 3Ask who reads the contract when a dispute starts, and whether they have read it before.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01


