FBI Removes Accenture Contractor Following Employee Data Breach

After the Federal Bureau of Investigation (FBI) experienced a breach of sensitive employee information, it was determined the incident was caused by a flaw in the third-party platform Accenture.
Brett Leatherman, assistant director of the FBI’s cyber division, told Reuters, “To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform.”
In response, the agency removed the contractor to mitigate further risk.
Kevin Surace, CEO at Token, comments, “What makes this incident so troubling is that this was not some mysterious new zero day attack. It was a well known, critical vulnerability rated 9.8 out of 10, which essentially means patch it urgently, and Oracle had already issued the fix. Accenture reportedly failed to implement that patch, leaving the vulnerable system exposed. ShinyHunters was likely scanning large numbers of systems looking for exactly this situation: an internet facing endpoint that remained unpatched. They found one. The attackers did not need to invent a sophisticated new technique; they simply exploited a known vulnerability that should have already been closed.
“This was an entirely preventable breach and a stark reminder that basic patch management remains one of the most important disciplines in cybersecurity.”
Jeff Wichman, Senior Director of Breach Preparedness & Response at Semperis, adds, “When organizations rely on contractors or third parties to manage their systems, they still own the risk. Outsourcing operations does not mean outsourcing accountability. I often hear people talk about transferring the risk to a vendor, but that is not how it works. An organization that takes a hands-off approach to maintaining, monitoring and securing its systems will still be the one dealing with the fallout when a breach occurs.
“The recent FBI incident is a clear example. The FBI removed a contractor after a breach exposed sensitive personal information belonging to thousands of bureau employees. According to the FBI, the contractor failed to apply a security patch that had been specifically issued to protect the platform. Whatever the contractor’s failure, the FBI is the organization dealing with the exposure of its own workforce. Oversight of critical systems cannot be delegated along with the work. The FBI should have been actively verifying that its contractor was applying patches on schedule through compliance monitoring, audits and regular patch-status reporting.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





