FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

https://www.securityweek.com/wp-content/uploads/2024/09/hack.jpeg

The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter.

The FBI has not publicly named the contractor or the organization involved. However, a senior bureau official told Reuters that its review so far points to a security patch that had not been applied by the contractor responsible for the affected system.

“To date, our review has determined that the incident occurred as the result of a security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform,” FBI cyber chief Brett Leatherman said in a statement.

“As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce,” Leatherman added.

According to...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE