ShinyHunters FBI breach: missed PeopleSoft patch blamed

ShinyHunters FBI breach: missed PeopleSoft patch blamed

The FBI has removed a contractor whose failure to apply a security patch is believed to have opened the door to the ShinyHunters breach of the bureau's systems. The incident exposed personal information belonging to thousands of FBI employees.

Reuters reported the removal on Tuesday, citing two people familiar with the matter. According to those sources, the contractor worked for Accenture, and the affected system was Oracle's PeopleSoft human resources platform.

FBI points to an unpatched third-party platform

The bureau has not publicly identified the contractor or the company behind the platform. A senior FBI official did tell Reuters, however, that the review conducted so far traces the incident to a patch that was never applied.

"To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization - after a contractor failed to implement a security patch explicitly issued to secure the platform," said Brett Leatherman, the FBI's cyber chief.

"As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce," he added.

Accenture did not respond to questions about the contractor or the alleged patching lapse. In a statement, the company said it was "proud to support the mission of the FBI and will continue to do so."

PeopleSoft already on the radar

The PeopleSoft link is not new. ShinyHunters had earlier claimed it used PeopleSoft to get into the FBI's job site. Google also recently warned that the group had been going after vulnerable PeopleSoft instances to steal data.

The cybercrime group announced the FBI hack on September 22. It said it had targeted the agency's jobs website and obtained information on all employees, including sensitive data. Some of that material was leaked to the media.

According to the hackers, the goal was to pressure the FBI into correcting or withdrawing a report the bureau published in May. That report warned organizations about ShinyHunters attacks, and the group claimed it contained false allegations.

Arrests in the Netherlands and Jordan

Law enforcement pressure on the group has been building. Shortly after ShinyHunters went public with the FBI breach, authorities said an alleged leader of the group had been arrested in the Netherlands on September 15.

The group did not back down right away. It urged its victims to keep negotiating and threatened to publish their data unless they paid.

On October 3, news emerged of the arrest of another alleged leader, Saif al-Din Khader, who goes by the alias Rey. He was reportedly detained in Jordan and has been cooperating with authorities.

ShinyHunters' website was still online at the time of the original report. A post pushing organizations to pay has been taken down, though, and the latest victim listing is dated September 22.

Our Take

The FBI's explanation is a familiar one. A vendor had released a fix, the fix existed, and it simply was not applied on a system run by an outside party. For organizations that hand over HR, payroll or other back-office platforms to service providers, this case is a reminder that outsourcing a system does not outsource the risk. Employee records held in an HR platform are exactly the kind of data that groups like ShinyHunters can use for leaks, extortion and further targeting.

It also fits a wider pattern. Patch windows are shrinking, and vulnerability disclosures keep climbing, which puts more strain on the teams responsible for keeping third-party systems current. Google's warning about ShinyHunters scanning for vulnerable PeopleSoft instances suggests the group was working through a known weakness rather than relying on something exotic. Organizations running PeopleSoft would be wise to check their patch status and ask their providers for proof, not just assurances.

The removal of a single contractor may also raise questions about accountability further up the chain. Accenture has not addressed the alleged failure, and it is worth watching whether contract terms, audits or patch reporting requirements for federal suppliers change as a result.

On the enforcement side, the arrests in the Netherlands and Jordan follow other recent actions against cybercrime crews, such as the KillSec takedown and the court appearance of the alleged Ploutus ATM malware developer. The removal of the pay-up post and the lack of new victim listings since September 22 could indicate that ShinyHunters is under real pressure. Groups like this have regrouped before, however, so it is too early to treat the silence as the end of the operation. The next things to watch are whether Rey's cooperation leads to more arrests and whether more of the stolen FBI data surfaces.