This is the kind of press a contractor dreads. Reuters reports that the FBI has removed an Accenture contractor on Monday because its failure to patch a vulnerability in Oracle’s PeopleSoft in a timely manner reportedly allowed the troubling FBI data breach by ShinyHunters.
In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update — or patch — the system they were responsible for.
“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in the statement. “As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.”
… sources also said the third-party organization was Accenture. Reuters could not immediately identify the specific contractor or determine their current employment status.
Read more at Reuters.
