The FBI has removed a contractor linked to a third-party technology provider after a security lapse exposed sensitive personal and employment information belonging to thousands of bureau employees, according to Reuters.
The contractor was removed on October 5 after the FBI found that a required security patch had not been installed on a third-party managed platform. The incident has raised concerns around patch management and the security risks associated with outsourced technology systems.
The information exposed included details about employees’ counterintelligence responsibilities, addresses of human intelligence operatives, as well as medical and psychiatric records. The FBI has not disclosed the exact number of employees affected, but the incident reportedly involved personal information belonging to thousands of workers.
The FBI said its review identified a security failure involving a third-party managed system and that steps had been taken to mitigate further risks and protect employees. The bureau has not publicly identified the platform or the organisation responsible for managing it.
However, sources cited by Reuters identified the platform as Oracle PeopleSoft and the third-party organisation as Accenture.
The incident has renewed attention on vulnerabilities associated with PeopleSoft. Earlier this year, security warnings were issued over attacks targeting organisations using the HR software platform. Google had also warned organisations about a hacking and extortion campaign linked to the ShinyHunters group, while Oracle issued a security alert concerning a PeopleSoft vulnerability and urged users to apply available security updates.
The breach highlights the risks employers face when critical employee systems are managed by external technology providers. HR, payroll and workforce platforms often contain highly sensitive personal information, making timely security updates and clear accountability between organisations and vendors particularly important.
The FBI continues to assess the scope of the incident and has not disclosed whether further action will be taken against vendors involved in managing the affected system.
