
FBI Removes Contractor Over Missed Patch in Portal Breach
The FBI removed an Accenture contractor after a missed patch on a human resources and applicant tracking software portal exposed employee data, Reuters reports.
The U.S. Federal Bureau of Investigation has removed an Accenture contractor for an alleged role in a ShinyHunters breach that led to the theft of personal details of thousands of bureau employees, according to a Reuters report citing two sources familiar with the matter. The incident marks a significant failure in patch management on a third-party managed platform, and it highlights how a single missed security update can cascade into a large-scale data exposure.
Brett Leatherman, assistant director of the FBI's cyber division, told Reuters that the bureau's review determined the incident occurred because of a security failure on a platform managed by a third-party organization after a contractor failed to implement a security patch explicitly issued to secure the platform. Leatherman added that the FBI removed the contractor and took all necessary steps to mitigate further risk and protect its workforce. While the FBI did not publicly name the third-party organization, Reuters reported that it is a widely used suite of human resources and applicant tracking software. The ShinyHunters group claimed last month that it exploited this platform to breach the FBI's job portal.
According to a report from Google-owned Mandiant, ShinyHunters is assessed to be exploiting a bypass for CVE-2026-35273, a specific vulnerability identifier. The bypass uses a URL-encoding trick to get around a web application firewall (WAF) rule designed to block the vulnerable Environment Management Hub endpoint. A WAF is a security filter that sits in front of a web application to block malicious traffic, and URL encoding is a technique that changes characters into a format that the firewall may not recognize, allowing an attacker to slip through. The Environment Management Hub endpoint is a management interface within the human resources and applicant tracking software suite that, when left unpatched, can give attackers unauthorized access.
Accenture, in a statement shared with Reuters, said it was proud to support the mission of the FBI and will continue to do so. The Hacker News has contacted both the FBI and the software vendor for comment and will update the story if either responds. The development is the latest twist in the operational history of ShinyHunters, a cybercriminal group known for stealing and selling data. The FBI has already arrested two members of the group as part of its ongoing investigation into the breach, and the agency said it is actively working with partners to obtain and execute more leads, warning that more arrests are likely to come.
For website owners and IT teams, this incident is a stark reminder that security patches must be applied promptly, especially on internet-facing platforms like job portals, HR systems, and other third-party services. A single overlooked update can expose sensitive personal data. For organizations that run their own web platforms, using a managed hosting provider that includes security updates can reduce that risk. AEU Hosting, for example, offers managed WordPress hosting with end-to-end security, which helps ensure that sites stay updated and protected without requiring manual patch management from the customer.
The FBI breach also shows why organizations should monitor third-party vendors and contractors closely, verify that security updates are actually applied, and have a clear incident response plan. For individuals whose data may have been exposed, it is important to watch for phishing attempts and monitor financial accounts. The ShinyHunters group has a history of selling stolen data, so affected employees should be cautious about unsolicited communications.
How to Protect Yourself
- If you applied for a job through an FBI portal or any government job site, watch for suspicious emails or texts asking for personal information.
- Turn on automatic updates for all software and apps on your devices to get security fixes as soon as they are released.
- Use a password manager to create unique passwords for every account, and change passwords for any account that may have been affected.
- Check your credit reports and financial accounts regularly for unfamiliar activity.
- Be cautious of urgent requests for personal details, even if they appear to come from an employer or government agency.
- Enable two-factor authentication (a second login step, like a code from your phone) wherever possible.
Vulnerabilities & Fixes
- CVE-2026-35273 A vulnerability identifier for a flaw in the human resources and applicant tracking software suite that ShinyHunters exploited via a URL-encoding bypass of a WAF rule. View the fix & details →
Terms Explained
- CVE-2026-35273 A unique number given to a known security flaw in the human resources and applicant tracking software suite, which attackers exploited to break in.
- web application firewall (WAF) A security tool that sits in front of a website to block harmful traffic before it reaches the site.
- Human resources and applicant tracking software suite A software suite used by organizations to manage human resources, job applications, and other employee-related tasks.
- Environment Management Hub A management interface in the human resources and applicant tracking software suite that attackers targeted to gain unauthorized access when it was not patched.
- URL encoding A way of changing characters into a different format so that a security filter does not recognize them, allowing an attacker to sneak past.
- ShinyHunters A cybercriminal group known for stealing and selling data from organizations.