Accenture's Source Code and Cloud Keys Listed for Sale Online
Accenture, a global consulting and IT services firm that works with major corporations and governments worldwide, has confirmed it was breached after a hacker going by "888" began selling stolen data on a cybercrime forum, according to Bleeping Computer.
The threat actor claims to have taken just over 35 GB of data. The alleged haul includes source code, RSA keys (private encryption credentials), SSH keys (used to authenticate into servers remotely), Azure PAT tokens (personal access tokens that grant programmatic access to Microsoft Azure cloud services), storage access keys, and configuration files. As proof, the attacker shared a screenshot showing them cloning an internal Azure DevOps repository under an Accenture hostname.
Accenture confirmed the incident, saying the source had been remediated and that operations were unaffected. The company did not comment on what was actually taken, how the attackers got in, or whether any customer data was exposed.
This is not a first offence for either party. The same "888" actor previously tried to sell Accenture employee data after a third-party breach in 2024. The LockBit ransomware group also hit Accenture in 2021.
The real concern here is the type of data reportedly stolen. Source code and cloud access tokens are not just embarrassing to lose — they are keys to the kingdom. An attacker holding a company's Azure access keys can potentially reach anything that company stores or builds in the cloud.
What you should do: If your organisation uses Accenture-managed services or shared cloud environments, contact your account team to confirm whether your infrastructure was within scope of the affected systems.
Sources

