Skip to content
Bramble

US

FBI removes Accenture contractor over data breach exposing employees' personal details

The FBI removed a contractor on 5 October over a breach that exposed sensitive details of thousands of bureau employees. Two sources told Reuters the platform was Oracle's PeopleSoft and the third-party organisation was Accenture.

2 outlets · 0L · 1C · 1R First reported Account updated
Image: CNA
Image: The Straits Times

1 / 2

The story, neutrally told

Mixed · 2The FBI removed an Accenture contractor on 5 October over their role in a data breach that exposed sensitive personal details of thousands of bureau employees, according to two sources familiar with the matter who spoke to Reuters. Centre · 1In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update, or patch, the system they were responsible for. Mixed · 2FBI cyber chief Brett Leatherman said the FBI's review so far found the incident resulted from a security failure of a platform managed by a third-party organisation after a contractor failed to implement a security patch "explicitly issued to secure the platform". He said the FBI had removed the contractor and taken all necessary steps to mitigate further risk and protect its workforce.

Mixed · 2The FBI did not name the platform or the third-party organisation. The two sources said the platform was Oracle's PeopleSoft, a human resources platform, and that the third-party organisation was Accenture. Mixed · 2The hacking group ShinyHunters said it exploited PeopleSoft to break into the FBI's job site last month. The Straits Times' version adds that the group said on 22 September that it had breached the FBI and stolen data on a large number of current and former employees. Mixed · 2Accenture said it was "proud to support the mission of the FBI and will continue to do so" but did not answer questions about the contractor or the alleged failure to patch. Oracle did not immediately reply to a request for comment.

Centre · 1Reuters could not identify the specific contractor or determine their current employment status.

Every sentence links to the reporting it rests on. The pill in front of each says where its sources sit: Left, Centre or Right when one side supplies at least half of them, Mixed when they are evenly split. The number is how many outlets it cites.

Left0 outlets

No left outlet in our sources has covered this story yet.

Centre1 outlet

Framing
Presented as a Reuters exclusive: CNA leads with the removal of the Accenture contractor and relies on anonymous sources.
Emphasis
The contractor's removal, the FBI's statement on the missed patch, and the sourcing of the Accenture and PeopleSoft details.
Leaves out or plays down
The Straits Times copy's 22 September date for ShinyHunters' claim of data theft.
Charged language
“damaging data breach”
For example
“Exclusive-Accenture contractor removed from FBI following damaging data breach, sources say” — CNA

Right1 outlet

Framing
The Straits Times runs the same Reuters copy, leading with the contractor's failure to patch the system and adding a standfirst on ShinyHunters' 22 September claim.
Emphasis
The patching failure and the hackers' claim of stealing data on current and former employees.
Leaves out or plays down
Does not carry the 'Exclusive' label.
Charged language
“damaging data breach”
For example
“The contractor had failed to properly update – or patch – the system they were responsible for.” — The Straits Times