The FBI has removed an Accenture contractor for allegedly failing to apply a security patch on a third-party platform, a lapse that let the ShinyHunters group breach the bureau’s jobs portal and expose personal details of thousands of FBI employees, according to Reuters. Separate reporting says an alleged ShinyHunters leader has been arrested in Jordan.
Missed Patch on an Oracle PeopleSoft Platform Opened the FBI Jobs Portal
Brett Leatherman, assistant director of the FBI’s cyber division, said the incident resulted from a contractor failing to implement a patch “explicitly issued to secure the platform.” Reuters identified the platform as Oracle PeopleSoft, which ShinyHunters said it exploited to reach FBIJobs.gov. The breach took place last month. Accenture said it was “proud to support the mission of the FBI.” The FBI’s own account, through Leatherman, is that a contractor did not implement a patch that had been issued to secure the platform.
Mandiant assesses that ShinyHunters is exploiting a bypass of CVE-2026-35273. The bypass uses a URL-encoding trick to evade a web application firewall rule that protects the PeopleSoft Environment Management Hub endpoint, known as PSEMHUB. The reporting does not spell out how the contractor’s missed patch relates to the firewall bypass, so the two details cannot yet be tied into a single attack path.
ShinyHunters Defacement and the 5,000-Record Sample
ShinyHunters defaced FBIJobs.gov and claimed to have stolen 2 to 3 terabytes of data. The group sent media outlets a sample of 5,000 FBI employee records and claimed to hold personal and health data on all current and former FBI employees. Only the sample has been described publicly, and the FBI has not confirmed the full scope of the claim.
Alleged ShinyHunters Leader Saif al-Din Khader Arrested in Jordan
Reuters separately reported that the suspected group leader, Saif al-Din Khader, who goes by “Rey,” has been arrested in Jordan. He is described as a teenager from Amman and is reportedly cooperating with the FBI to identify other members. He is also linked to Scattered Lapsus$ Hunters. Where he is being held is unclear.
The arrest was reported around October 4 and 5, and the contractor’s removal followed on October 5 and 6. In sequence, the breach happened in September, the Dutch arrest came last week, and the Jordan arrest and the contractor’s removal were reported within the past three days.
Dutch Arrest of a 24-Year-Old Preceded the Jordan Detention
Last week, Dutch police arrested a 24-year-old man in Amsterdam. The FBI said he was involved in hacking more than 140 organizations and in collecting at least $70 million in extortion payments. Independent reports suggest he is Pepijn van der Stap, who was previously convicted in 2023, though the FBI has not confirmed the name. FBI Director Kash Patel said “More arrests are on the table.”
Two arrests in about a week, in two countries, have followed. The Jordan suspect is reportedly cooperating with the FBI to identify other members, and Patel’s statement points to further arrests.
Third-Party Patch Failures Become an Accountability Question for Federal Contractors
The FBI’s decision to publicly remove a contractor over a missed patch is a direct public assignment of blame to a vendor. Leatherman’s wording places responsibility on the contractor rather than on the platform vendor, and the breach exposed personal details of thousands of FBI employees.
Accenture’s response so far consists of a statement of support for the FBI mission. The Hacker News had contacted the FBI and Oracle for comment, and the reporting available includes no response from either. Whether other agencies that run PeopleSoft through contractors will review their own patch records is an open question, as is whether the arrested suspects will face charges tied to the FBI intrusion itself.
