FBI Removes Accenture Contractor After Major Oracle Data Breach
The FBI removed an Accenture contractor after a security failure in an Oracle platform exposed sensitive employee data and medical records of millions.
The Federal Bureau of Investigation removed an Accenture contractor on Monday following a data breach that exposed sensitive personal information of thousands of employees. The compromised data included medical and psychiatric records, counterintelligence role descriptions, and the street addresses of human intelligence operatives. FBI Cyber Chief Brett Leatherman stated the incident occurred because a contractor failed to implement a security patch explicitly issued to secure a platform managed by a third-party organization.
Sources identify the compromised platform as Oracle's PeopleSoft, which the hacking group ShinyHunters claimed to have exploited to enter the FBI's job site last month. Oracle and Google had previously warned of vulnerabilities in PeopleSoft in June. A key suspect linked to ShinyHunters was recently detained in Jordan and is reportedly cooperating with authorities.
This incident follows a separate report released Friday by the Texas attorney general detailing a breach of Oracle Corp.'s healthcare unit. That attack compromised the personal information of nearly 20 million people, including Social Security numbers and medical data, with approximately 3 million victims residing in Texas. Oracle had alerted some customers to that specific breach in March 2025, noting it occurred after January 22, 2025.