Accenture has confirmed a security incident after a threat actor advertised 35GB of data allegedly stolen from the consulting giant — including source code, cryptographic keys, and cloud access tokens — for sale on an underground forum. The company describes the matter as “isolated” and already remediated, with no impact on operations or client service.
The actor, operating under the handle “888,” posted the listing on the cybercrime forum PwnForums, claiming to have exfiltrated “just over 35gb of source codes” from Accenture. The advertisement went beyond code.
The keys are the story
Source code theft is embarrassing; the credentials bundled with it are dangerous. According to the listing, “888” claims to have taken:
- Source code for internal and client-facing systems
- RSA and SSH keys
- Azure personal access tokens (PATs)
- Azure Storage access keys
- Configuration files
To back the claim, the actor posted a screenshot showing data exfiltration from a private Azure DevOps repository hosted on a production URL associated with an accenture.com domain. If the cryptographic material is live, the exposure is not merely intellectual property — it is a set of working keys to cloud storage, source control, and remote systems. Access tokens and storage keys are exactly the artifacts that let an attacker move from “we have your code” to “we have your infrastructure,” which is why the type of data here matters more than the raw 35GB figure.
Accenture’s response
Accenture confirmed to reporters that it was aware of an “isolated matter” and said the source had already been remediated, with no impact to operations or service delivery. The company has not detailed how the repository was accessed, whether any exposed keys have been rotated, or whether client data or client-owned code sits inside the stolen archive — the question that most concerns the enterprises that trust Accenture with their systems.
This is not “888’s” first alleged run at the firm. The actor reportedly claimed an Accenture breach in 2024 as well — an incident Accenture publicly disputed at the time. A repeat claim, this time with repository screenshots attached, raises the bar on what the company will need to show to call this fully contained.
Why the IT-services sector keeps bleeding
The breach lands in the middle of a rough stretch for professional-services and consulting firms — the organizations that hold other companies’ code, credentials, and regulated data by the terabyte. Just today, fellow Big Four-tier firm Ernst & Young disclosed its second breach in nine months, this one exposing client tax records through a third-party support platform.
The common thread is not sophistication. It is the enormous concentration of sensitive material — source code, keys, tokens, client data — inside firms whose brand is built on managing risk for everyone else. When a single private DevOps repo can yield RSA keys, SSH keys, and Azure tokens in one archive, the blast radius of one compromised repository extends to every system those secrets unlock. Secrets sprawl in source control remains one of the most reliably exploited weaknesses in the enterprise, and consulting firms sit on more of it than almost anyone.
What this means for Accenture clients
Organizations that share code or infrastructure with Accenture should:
- Ask directly whether their code, credentials, or data are within scope of the stolen archive.
- Rotate any shared secrets — SSH keys, API tokens, storage keys — that Accenture engineers may have held.
- Audit access logs on shared cloud tenants and repositories for anomalous use of PATs or storage keys.
“Isolated and remediated” is the right thing to say on day one. Whether it holds depends on what, exactly, is in the 35GB — and Accenture has not yet said.
Sources
- BleepingComputer — Accenture confirms breach after hacker offers stolen data for sale
- Help Net Security — Accenture acknowledges security incident following 35GB data theft claim
- Cybersecurity Dive — Accenture data breach: access keys, source code
- TechRadar — Accenture confirms breach after hacker steals 35GB of source code and other data

