The FBI removes an Accenture contractor after an alleged breach that exposed personal data of thousands of bureau employees. Reuters, cited by multiple outlets, reports that the bureau’s internal review finds the incident stems from a security failure related to a third-party-managed system.

A senior FBI official says the breach occurs because a security patch issued for the platform was not applied by the contractor responsible for implementing it. The FBI also takes steps to mitigate further risk and protect its workforce, including removing the contractor. While outlets reference Reuters’ reporting that the platform involved may be Oracle’s PeopleSoft and that the ShinyHunters group claimed responsibility, the FBI does not publicly name the affected platform or the third-party organization.

Accounts also differ in what additional details they emphasize. One report focuses on the FBI’s security patch failure and contractor removal, while others highlight the type and sensitivity of information reportedly accessed, including personal, operational, and health-related data tied to FBI personnel. Oracle and Accenture respond publicly with statements that do not confirm the specific patching issue or contractor details, according to the cited reporting.