Accenture contractor removed over blunder in lead up to FBI breach

The contractor is believed to have failed to apply a security patch that would have secured Oracle PeopleSoft

FBI logo and insignia pictured on a wall alongside a United States flag at the Los Angeles Federal Building.
(Image credit: Getty Images)

The FBI has reportedly removed an Accenture contractor in connection with the recent data breach that exposed sensitive information on thousands of employees.

Data stolen in the incident is believed to have included descriptions of counterintelligence workers' roles, the home addresses of human intelligence operatives, and even the medical and psychiatric records of bureau employees.

The breach, revealed last month, involved a compromise of the FBI’s jobs portal. It was claimed by ShinyHunters, which said it had exploited a vulnerability in Oracle PeopleSoft, an enterprise resource planning (ERP) suite used in human resources (HR), finance, and supply chain management.

FBI cyber chief Brett Leatherman told Reuters the contractor failed to apply the appropriate patch.

Latest Videos FromIT Pro

“To date, our review has determined that the incident occurred as the result of a security failure ​of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the ​platform," he said.

"As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”

Responsibility lies with the organization

It's not clear why the contractor failed to apply the patch. While the removal of the contractor implies it was negligence, David Neeson, SOC deputy team lead at Barrier Networks, suggested that there might have been a good reason, such as a possible impact on another critical system.

"Leadership must always be accountable for security decisions, so if the patch not being applied was out of the contractor’s control, then the FBI could be making a dangerous mistake with their removal. It could also spur other organizations to take similar action when they are trying to shift responsibility around the cause of an attack," he said.

"Patch management is never simple, and the FBI must clearly understand this.”

This view is echoed by Jason Brown, director of customer advisory and counter fraud lead at iCounter, who said that accountability should always reside with the organization itself.

"Every contract for a managed platform should spell out how quickly critical patches have to be applied, require the third party to prove it was done, and give the customer the right to check," he said.

"Security teams also need to stop treating third-party managed systems as someone else's problem. Keep an inventory of every platform a third party runs on your behalf, know what data sits in it, and watch for warning signs, like that platform showing up in exploit activity or criminal forums."

Extortion group ShinyHunters has been operating since 2019, with members apparently coming from all over the world. Since that time, the group has been associated with a number of major breaches, including the European Commission, Snowflake, LastPass, Okta, AMD, and Salesforce.

International law enforcement bodies have been working to take down ShinyHunters for some time, most recently with the arrest of a 24-year-old Dutch man last month and another man in Jordan this week. Detainees are reported to be cooperating with the FBI.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

TOPICS
Emma Woollacott

Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.