Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

FBI Blames Contractor’s Missed PeopleSoft Patch for ShinyHunters Breach: A Warning for Canadian Organizations

What Happened

The FBI says an Accenture contractor failed to apply a patch on an Oracle PeopleSoft platform, and ShinyHunters walked in. The Hacker News reports the flaw is CVE-2026-35273 on the PSEMHUB endpoint. Attackers used URL encoding to slip past web application firewall rules. They stole personal details of thousands of FBI employees through the bureau’s job portal.

FBI cyber division assistant director Brett Leatherman said the incident followed a security failure after a contractor missed an explicitly issued patch. The FBI removed the contractor and applied mitigations. Two group members are under arrest, with more arrests expected, according to SecurityWeek.

Why This Matters for Canadian Organizations

The breach is a vendor accountability story. The fix existed. The contractor owned the system. The agency still absorbed the damage and the headlines. Canadian federal departments, provinces, municipalities, and universities outsource ERP and HR platform operations in the same way, and many run PeopleSoft.

The same exposure applies under Canadian privacy law. PIPEDA and provincial statutes keep the organization accountable for personal information held by a service provider. A contractor’s missed patch does not move the breach notification duty to the contractor. Applicant and employee data also carries high identity theft value.

What to Do

Read your outsourcing contracts and name who patches each internet-facing system. Set a patch deadline in writing, and require proof of completion. Ask for a monthly list of exposed systems and open critical fixes. Confirm your own team applied the Oracle fix for CVE-2026-35273. Do not rely on a web application firewall alone, since this attack bypassed one. Review our daily briefs and TechTalk coverage for related patch alerts.

Enjoy this article? Don’t forget to share.