FBI Removes Accenture Contractor Over Oracle Patch Failure After ShinyHunters Breach

The FBI has terminated its working relationship with an Accenture contractor following a breach linked to ShinyHunters that exposed personal data of bureau employees. An internal review found the breach resulted from a third-party platform failing to implement a critical patch that Oracle had issued. As part of damage control, the contractor was removed, and the FBI says it has moved to protect its personnel.

What Went Wrong: Unpatched Oracle PeopleSoft Component

The platform at the center of the breach is identified by multiple sources as Oracle PeopleSoft, specifically its Environment Management Hub (PSEMHUB) endpoint. ShinyHunters exploited CVE-2026-35273, a severe unauthenticated remote code execution vulnerability that Oracle patched in early June. The vulnerability arises from a Java deserialization flaw within the PSEMHUB hub servlet.

Although Oracle released a security alert and patch on June 10, 2026, attackers had already exploited the flaw between May 27 and June 9. Many organizations had responded by using WAFs or network rules to block the literal path “/PSEMHUB/,” but these mitigations proved insufficient. In a new wave of attacks, ShinyHunters bypassed those protections by URL encoding the path—using “/%50SEMHUB/” instead of “/PSEMHUB/.” While the WAF checked the unmodified path, Oracle’s servers decode it and allow it through.

Scope & Fallout

The exploit campaign has hit over 100 organizations globally, many in higher education but stretching across sectors like government, healthcare, agriculture, and transportation. Tens of thousands of systems are believed vulnerable, with hundreds of affected PeopleSoft instances.

In the FBI’s case, the breach exposed job-portal data, including personal information of existing and prospective employees. The bureau says the contractor had been explicitly instructed to apply Oracle’s security patch and had failed to do so. The third-party platform was compromised via this oversight; in response, the contractor was removed, and mitigation efforts to protect affected employees are underway.

Authorities are still investigating how much data was stolen, but reports suggest the sensitive information could include home addresses, medical records, and employee identifiers. Two ShinyHunters members have already been arrested, and the FBI has indicated more arrests are likely as the investigation continues.

Action Steps Organizations Should Take

  • Ensure the Oracle patch for CVE-2026-35273 has been applied immediately.
  • Disable or remove PSEMHUB/Environment Management Hub service where it’s exposed, especially in single-server setups.
  • Search logs for both “/PSEMHUB/” and encoded variants like “/%50SEMHUB/” to detect bypass attempts.
  • Inspect the PSEMHUB.war directory for unexpected files (e.g..jsp web shells) or suspicious indicators such as unexpected directories or outbound SMB activity.
  • Rotate any credentials accessible via the vulnerable components, such as service-account or database credentials.

The FBI incident puts a spotlight on the risks of depending on third parties for critical infrastructure management. Even when patches are issued, delays in implementation leave systems vulnerable—especially when attackers can evade superficial defenses like improperly configured WAF rules.