FBI removes Accenture contractor after missed security patch led to breach

Joan Cros/NurPhoto via Getty Images

The bureau’s cyber chief blamed a contractor’s failure to apply an available fix for an intrusion that may have exposed sensitive employee information.

The FBI has severed ties with a contractor working for Accenture amid a massive cybercrime intrusion that may have exposed data on thousands of bureau employees, according to a person with knowledge of the matter.

Prolific cybercrime group ShinyHunters claimed responsibility for the hack last month. The data stolen contained employees’ addresses, phone numbers and information on their spouses, among other categories. It also revealed sensitive data on employees’ intelligence and surveillance roles, as well as private medical information.

Accenture is responsible for software patch management and maintaining custom code at the FBI, said the person, who spoke on the condition of anonymity because the situation is sensitive. Oracle — whose PeopleSoft platform was the initial access point that ShinyHunters claimed to have exploited — provided the security patches that were not integrated, the person added.

FBI cybersecurity chief Brett Leatherman confirmed the removal of an unnamed contractor in a statement to Nextgov/FCW.

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” Leatherman said. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”

The remarks offer the bureau’s clearest explanation yet of how the intrusion occurred, though they do not address why the patch was missed and how the FBI monitored the contractor’s work to ensure systems holding sensitive employee information were protected.

Reuters first reported the removal late Monday. The specific Accenture employee could not be immediately identified.

In a statement, the company said it’s “proud to support the mission of the FBI and will continue to do so.”

The breach follows recent findings from Google’s Mandiant that ShinyHunters had resumed widespread exploitation of a PeopleSoft vulnerability for which Oracle issued a patch in June. 

The incident poses serious counterintelligence risks because the exposed records could help foreign intelligence services identify employees working on sensitive investigations and exploit personal information about them. 

ShinyHunters has said it would not publish the stolen data, but its statement did not say the records had been deleted. Retired Lt. Gen. Robert Skinner, who previously led the Defense Information Systems Agency, told Nextgov/FCW last week that the group could still sell some or all of the information to foreign intelligence services or other buyers.

Authorities have also moved against suspected members of the group. Dutch police last week announced the arrest of an alleged leader, and Reuters reported Saturday that another suspected member, Saif al-Din Khader, had been detained in Jordan and was helping investigators locate other hackers.