Summary
Global consulting and IT services giant Accenture has confirmed a security breach after a threat actor known as “888” claimed to have stolen 35 GB of data from the company and began offering it for sale on a cybercrime forum. The stolen data allegedly includes source code, RSA keys, SSH keys, Azure personal access tokens (PATs), Azure Storage access keys, and configuration files.
To support the claims, the threat actor shared a screenshot showing them cloning an Azure DevOps repository hosted under an Accenture domain. Accenture acknowledged the incident as an “isolated matter” and stated it had remediated the source, with no impact on operations or service delivery. However, the company declined to comment on the scope of exfiltrated data or how the attackers gained access.
This is not Accenture’s first rodeo โ the same threat actor previously attempted to sell Accenture employee data following a third-party breach in 2024, and the company suffered a LockBit ransomware attack in 2021.
Source
BleepingComputer ยท Help Net Security
Commentary
When 35 GB of source code, cryptographic keys, and cloud access tokens from a Fortune 500 consulting firm hit the market, “isolated matter” doesn’t quite capture the gravity. RSA keys, SSH keys, and Azure PATs are the crown jewels โ if legitimate, they could enable lateral movement across client environments, not just Accenture’s own infrastructure.
The recurring pattern here is notable: the same threat actor targeting Accenture across multiple years suggests either persistent access or that the company’s attack surface remains attractive. For Accenture’s clients, the key question isn’t whether Accenture’s operations are intact โ it’s whether any of those stolen credentials provide a bridge into their own environments.
