The FBI says the theft of personal data on thousands of its staff happened because a contractor did not apply a security patch to a platform it managed. According to Reuters, that platform is Oracle PeopleSoft, affected by CVE-2026-35273 (CVSS 9.8), fixed by Oracle in June and listed by CISA as actively exploited.
What happened
In September 2026 the ShinyHunters extortion group claimed it had broken into the FBI’s job application portal. The bureau has now explained how. In a statement quoted by Reuters, Brett Leatherman, assistant director of its cyber division, said the incident came from a security failure on a platform managed by a third party, after a contractor failed to install a patch issued specifically to secure it. The FBI says it has removed that contractor. According to The Hacker News, personal details of thousands of employees were stolen; The Record reports that the leaked records included home addresses and Social Security numbers. Two suspected members of the group have been arrested.
How the attackers got in
The FBI did not name the platform; Reuters identifies it as Oracle PeopleSoft. The flaw, CVE-2026-35273 (CVSS 9.8), sits in the Environment Management component of PeopleSoft PeopleTools 8.61 and 8.62: no account is needed, one HTTP request is enough, and Oracle warns it can lead to remote code execution. Oracle published an emergency Security Alert on 10 June 2026, and CISA added the flaw to its catalogue of exploited vulnerabilities on 12 June.
According to a Mandiant analysis reported by The Hacker News, the attackers also defeated firewall rules meant to block the vulnerable /PSEMHUB/ endpoint by URL-encoding a single letter (/%50SEMHUB/), then dropped JSP web shells and remote-access tools.
What to do now
- Apply Oracle’s fix for CVE-2026-35273 on every PeopleTools 8.61 or 8.62 environment, test and pre-production included.
- Disable or remove the Environment Management Hub (PSEMHUB) if you do not use it, instead of relying on a WAF rule alone.
- Search the web server logs for calls to this endpoint, encoded or not, for example with
grep -ri semhub /path/to/logs, and decode URLs before matching. - Look for unexpected JSP files in the PSEMHUB application directories, e.g.
find / -path '*PSEMHUB*' -name '*.jsp'. - Rotate the credentials reachable from PeopleSoft service accounts if you find any trace of compromise.
Our take
Oracle’s fix had been available since June: the weak point was not technical but organisational. When a provider runs one of your servers, write into the contract how quickly critical patches must be applied, and check it yourself. A WAF rule is a stopgap, never a substitute for the patch.
Sources
- Oracle — Security Alert Advisory CVE-2026-35273
- CISA — Known Exploited Vulnerabilities Catalog, CVE-2026-35273
- The Hacker News — FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
- The Hacker News — Attackers bypass WAFs to exploit Oracle PeopleSoft
- The Record — Alleged ShinyHunters member detained in Jordan
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert