FBI contractor removed after data breach due to unapplied security patch
What happened
The FBI confirmed a security failure on a platform managed by a third party led to a data breach (an incident in which data leaves an organisation without permission) affecting thousands of employees, according to a recent report by Information Week. Application security , Third-party code , Threat Intelligence FBI contractor removed after data breach due to unapplied security patch October 11, 2026 Share By SC Staff (Adobe Stock) The FBI confirmed a security failure on a platform managed by a third party led to a data breach affecting thousands of employees, according to a recent report by Information Week.
The incident occurred because a contractor failed to implement a critical security patch for Oracle's PeopleSoft ERP software. This vulnerability, identified as CVE-2026-35273 (the public catalogue number for a specific software flaw), was exploited by threat actors (the person or group behind an attack) like ShinyHunters (criminal internet hacker group), who modified their attacks to bypass existing security measures. The FBI's experience highlights a growing challenge for organizations: ensuring timely patching when responsibility is distributed across multiple external entities.
Sources & evidence
- SC Media Reporting source
FBI contractor removed after data breach due to unapplied security patch ↗
https://www.scworld.com/brief/fbi-contractor-removed-after-data-breach-due-to-unapplied-security-patch