FBI removes Accenture contractor over data breach on Oracle PeopleSoft
The FBI removed an Accenture contractor over their role in a data breach that exposed employee details, after the contractor failed to implement a security patch for Oracle's PeopleSoft platform, two sources told Reuters.
(Adds comment from FBI and Accenture and attempt to reach Oracle in paragraphs 2-7) By Jana Winter and Raphael Satter WASHINGTON, Oct 5 (Reuters) — The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees, two sources familiar with the matter told Reuters. In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update — or patch — the system they were responsible for.
"To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform," FBI cyber chief Brett Leatherman said in the statement. " The FBI did not identify the platform or third-party organization, but the two sources familiar with the matter said the platform was Oracle's PeopleSoft, a human resources platform that the hacking group ShinyHunters said it exploited to break into the FBI's job site last month. Oracle did not immediately reply to a request for comment.
The sources also said the third-party organization was Accenture. Reuters could not immediately identify the specific contractor or determine their current employment status. " It did not answer questions about the contractor or their alleged failure to patch. com; +1 202 430 9389;)