FBI removes Accenture contractor over data breach exposing employees' personal details
The FBI removed a contractor on 5 October over a breach that exposed sensitive details of thousands of bureau employees. Two sources told Reuters the platform was Oracle's PeopleSoft and the third-party organisation was Accenture.
1 / 2
The story, neutrally told
Mixed · 2The FBI removed an Accenture contractor on 5 October over their role in a data breach that exposed sensitive personal details of thousands of bureau employees, according to two sources familiar with the matter who spoke to Reuters. CNAN “The Federal Bureau of Investigation removed an Accenture contractor on Monday over their role in a damaging data breach that exposed sensitive personal details” Read at CNA ↗ The Straits TimesRC “removed an Accenture contractor on Oct 5 over their role in a damaging data breach that exposed sensitive personal details of thousands of bureau employees” Read at The Straits Times ↗ Centre · 1In a statement to Reuters, a senior FBI official confirmed that an unidentified contractor had failed to properly update, or patch, the system they were responsible for. CNAN “a senior FBI official confirmed that an unidentified contractor had failed to properly update — or patch — the system they were responsible for.” Read at CNA ↗ Mixed · 2FBI cyber chief Brett Leatherman said the FBI's review so far found the incident resulted from a security failure of a platform managed by a third-party organisation after a contractor failed to implement a security patch "explicitly issued to secure the platform". He said the FBI had removed the contractor and taken all necessary steps to mitigate further risk and protect its workforce. The Straits TimesRC “after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in the statement.” Read at The Straits Times ↗ CNAN “the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.” Read at CNA ↗
Mixed · 2The FBI did not name the platform or the third-party organisation. The two sources said the platform was Oracle's PeopleSoft, a human resources platform, and that the third-party organisation was Accenture. CNAN “The FBI did not identify the platform or third-party organization, but the two sources familiar with the matter said the platform was Oracle's PeopleSoft” Read at CNA ↗ The Straits TimesRC “The sources also said the third-party organisation was Accenture.” Read at The Straits Times ↗ Mixed · 2The hacking group ShinyHunters said it exploited PeopleSoft to break into the FBI's job site last month. The Straits Times' version adds that the group said on 22 September that it had breached the FBI and stolen data on a large number of current and former employees. CNAN “the hacking group ShinyHunters said it exploited to break into the FBI's job site last month.” Read at CNA ↗ The Straits TimesRC “The hacking group ShinyHunters said on Sept 22 that they had breached the FBI, stealing data on a large number of current and former FBI employees.” Read at The Straits Times ↗ Mixed · 2Accenture said it was "proud to support the mission of the FBI and will continue to do so" but did not answer questions about the contractor or the alleged failure to patch. Oracle did not immediately reply to a request for comment. CNAN “Accenture said it was "proud to support the mission of the FBI and will continue to do so." It did not answer questions about the contractor or their alleged failure to patch.” Read at CNA ↗ The Straits TimesRC “Oracle did not immediately reply to a request for comment.” Read at The Straits Times ↗
Centre · 1Reuters could not identify the specific contractor or determine their current employment status. CNAN “Reuters could not immediately identify the specific contractor or determine their current employment status.” Read at CNA ↗
Every sentence links to the reporting it rests on. The pill in front of each says where its sources sit: Left, Centre or Right when one side supplies at least half of them, Mixed when they are evenly split. The number is how many outlets it cites.
Left0 outlets
No left outlet in our sources has covered this story yet.
Centre1 outlet
- Framing
- Presented as a Reuters exclusive: CNA leads with the removal of the Accenture contractor and relies on anonymous sources.
- Emphasis
- The contractor's removal, the FBI's statement on the missed patch, and the sourcing of the Accenture and PeopleSoft details.
- Leaves out or plays down
- The Straits Times copy's 22 September date for ShinyHunters' claim of data theft.
- Charged language
- “damaging data breach”
- For example
-
“Exclusive-Accenture contractor removed from FBI following damaging data breach, sources say” — CNA
Right1 outlet
- Framing
- The Straits Times runs the same Reuters copy, leading with the contractor's failure to patch the system and adding a standfirst on ShinyHunters' 22 September claim.
- Emphasis
- The patching failure and the hackers' claim of stealing data on current and former employees.
- Leaves out or plays down
- Does not carry the 'Exclusive' label.
- Charged language
- “damaging data breach”
- For example
-
“The contractor had failed to properly update – or patch – the system they were responsible for.” — The Straits Times
What every side reports
- The FBI removed a contractor on 5 October over a data breach exposing sensitive details of thousands of employees.
- FBI cyber chief Brett Leatherman said a contractor failed to implement a security patch on a third-party-managed platform.
- Two sources told Reuters the platform was Oracle's PeopleSoft and the organisation was Accenture; the FBI did not name either.
- Accenture did not answer questions about the contractor; Oracle had not replied.
Where accounts differ
-
Whether Accenture was the responsible third party
- Centre
- Reports it only as the account of two unnamed sources; the FBI did not name the organisation.
- Right
- Same Reuters account: attributed to two unnamed sources, with the FBI not naming the organisation.
FBI organisation
Says its review found the incident resulted from a contractor's failure to apply a security patch on a third-party platform, and that it removed the contractor and took steps to mitigate risk.
“the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce.” — CNA
Accenture organisation
Says it is proud to support the FBI's mission and will continue to; it did not answer questions about the contractor or the patch.
“It did not answer questions about the contractor or their alleged failure to patch.” — The Straits Times
Left0 articles
No coverage yet.
Centre1 article
-
CNAN ·
Exclusive-Accenture contractor removed from FBI following damaging data breach, sources say
Neutral Reuters exclusive carried by CNA, reporting the removal on the basis of unnamed sources and an FBI statement.
Right1 article
-
The Straits TimesRC · · via Reuters
Accenture contractor removed from FBI following damaging data breach, sources say
Neutral Reuters copy run by The Straits Times, leading with the missed patch and ShinyHunters' claim.
- 6 Oct 01:58 First CNAN Exclusive-Accenture contractor removed from FBI following damaging data breach, sources say
- 6 Oct 02:35 +37m The Straits TimesRC Accenture contractor removed from FBI following damaging data breach, sources say via Reuters
Times are when each article was published, or when we first saw it if the outlet gave no time.