The US Federal Bureau of Investigation has confirmed a major data breach, as a result of which hackers gained access to confidential information about thousands of current and former FBI staff members. The incident was caused by a critical security patch on the platform, which was maintained by a third-party company, failing to be applied in a timely manner. Following an internal investigation, the FBI suspended the contractor responsible.
- Hackers have obtained the personal data of thousands of FBI staff members.
- The leak was caused by a critical security patch that had not been installed.
- This refers to the Oracle PeopleSoft platform, which was managed by Accenture.
- The contractor in question has been barred from working with the FBI.
An unidentified patch granted access to the system
According to the head of the FBI’s cyber unit Brett Leatherman, an internal investigation found that the incident was caused by a security breach on a platform managed by a third-party organisation. According to him, the contractor responsible has not installed a security update released specifically for this purpose, which was intended to fix the vulnerability.
Reuters sources identified this platform as Oracle PeopleSoft — a human resources management system linked to the FBI’s recruitment portal. Accenture was responsible for maintaining the platform. The company confirmed that it continues to work with the FBI, but did not comment in detail on the situation regarding the specific employee.
Among the items stolen were agents’ addresses and medical records
The scale of the data breach turned out to be far more serious than a routine theft of contact details. Among the compromised data were job descriptions of counter-intelligence staff, home addresses of individuals linked to intelligence operations, and medical and psychiatric records of FBI staff.
It had previously been reported that social security numbers, information about family members and other personal data had been compromised. Once the scale of the attack had been established, the FBI assumed the worst-case scenario — that the data of all staff could potentially have been compromised, until an investigation proved otherwise.
For a law enforcement agency of this calibre, such a data breach is particularly dangerous: personal data could be used for surveillance, blackmail, phishing attacks or to identify individuals working on sensitive investigations.
ShinyHunters claimed responsibility for the attack
A hacker group claimed in September to have breached the FBI’s systems ShinyHunters. The hackers claimed to have obtained a large amount of information about current and former employees of the bureau. The FBI subsequently launched its own investigation and took steps to protect its systems and staff.
One of the suspected members of ShinyHunters was later arrested in Jordan. He is cooperating with the investigation and has granted the police access to some of his devices and communications.
Oracle had warned of the problem earlier
Oracle had previously issued warnings regarding PeopleSoft vulnerabilities and urged customers to install updates promptly. Google has also documented campaigns in which attackers exploited vulnerabilities in this platform.
У FBI They stated that, following the incident, they had dismissed the contractor responsible and taken the necessary measures to minimise future risks.







