The FBI confirmed a security failure on a platform managed by a third party led to a data breach affecting thousands of employees, according to a recent report by Information Week.
The incident occurred because a contractor failed to implement a critical security patch for Oracle's PeopleSoft ERP software. This vulnerability, identified as CVE-2026-35273, was exploited by threat actors like ShinyHunters, who modified their attacks to bypass existing security measures. The FBI's experience highlights a growing challenge for organizations: ensuring timely patching when responsibility is distributed across multiple external entities. Verizon's 2026 Data Breach Investigations Report indicates that vulnerability exploitation is now the leading initial access vector for breaches, with AI accelerating the timeline from vulnerability disclosure to exploitation. The FBI breach underscores the complexity of modern IT environments, where a single vulnerability can have far-reaching consequences due to the interconnectedness of vendors, managed service providers, and contractors. This fragmentation of control makes it difficult for any single entity to guarantee system security, as demonstrated by the 60% rise in breaches involving third parties.
Source: Information Week

