By Jana Winter and Raphael Satter
WASHINGTON, Oct 5 (Reuters) – The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters.
In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update — or patch — the system they were responsible for.
“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in the statement. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”
The FBI did not identify the platform or third-party organization, but the two sources familiar with the matter said the platform was Oracle’s PeopleSoft, a human resources platform that the hacking group ShinyHunters said it exploited to break into the FBI’s job site last month.
Oracle did not immediately reply to a request for comment.
The sources also said the third-party organization was Accenture. Reuters could not immediately identify the specific contractor or determine their current employment status.
In a statement, Accenture said it was “proud to support the mission of the FBI and will continue to do so.” It did not answer questions about the contractor or their alleged failure to patch.
(Reporting by Raphael Satter and Jana Winter; Editing by Christian Schmollinger)

