FBI Removes Accenture Contractor Following Employee Data Breach
The FBI fired an Accenture contractor after a security lapse exposed sensitive personal data of thousands of FBI workers. The hack apparently involved Oracle PeopleSoft software and a vulnerability that was thought to have been exploited by the ShinyHunters criminal gang.
An Accenture contractor was fired by the FBI following a data breach that exposed the personal information of thousands of FBI workers due to a security failure. A media report states that the FBI is currently in the process of determining the complete extent of the breach's impact, which previous bureau officials have characterised as a significant danger to the operational security of the agency.
According to a statement given to Reuters by FBI cyber chief Brett Leatherman, the incident happened because a contractor neglected to apply a security patch that was specifically issued to protect a third-party organisation's platform. This was found during an FBI investigation.
How Data Breach Happened?
The FBI has remained tight-lipped about the platform and third-party organisations that were participating. Nevertheless, sources informed Reuters that the platform was Oracle's PeopleSoft, a human resources software system, and the third-party organisation was Accenture. The incident is associated with a cybercrime campaign known as ShinyHunters, which has allegedly targeted businesses that use PeopleSoft software. Last month, the group claimed to have gained access to the FBI's employment website by utilising a PeopleSoft vulnerability.
Some FBI workers' counterintelligence responsibilities were exposed in detail in the leak, among other highly sensitive material. In addition, the hack exposed the physical addresses of agents in human intelligence as well as the medical and mental health records of bureau employees. The FBI chose not to say how much data was compromised or if hackers managed to steal all of the unsecured material. According to Leatherman, the FBI has terminated the contractor's agreement and is taking all required measures to safeguard our employees and prevent additional harm.
ShinyHunters Hacking the Most High-Tech Firms
Google alerted the public in June about a hack-and-extort effort targeting businesses using PeopleSoft software, which was related to ShinyHunters. Oracle also released a security notice that day, detailing a PeopleSoft vulnerability and the solutions it offered. Both businesses stressed the importance of organisations using PeopleSoft immediately installing all available security patches, updates, and alerts. In order to protect networks and devices from hackers, it is essential to quickly patch vulnerable software.
But it's not always easy or quick, especially when dealing with enterprise software that many people use. Everyone in the intelligence community, including the FBI, is worried about the hack. A prominent ShinyHunters suspect was apprehended in Jordan last week. The alleged hacker is reportedly cooperating, which might help the bureau determine the full extent of the damage or at least contain it, according to sources familiar with the situation. Accenture expressed its pride in its commitment to supporting the FBI's work in a statement. Concerning the contractor and their purported patching failure, it failed to provide any answers.