Accenture confirmed a cybersecurity breach after a threat actor using the name "888" advertised roughly 35 GB of alleged company data for sale on a cybercrime forum. The seller claimed the cache included source code, configuration files, RSA keys, SSH keys, Azure Personal Access Tokens, and Azure Storage access keys, and reportedly shared a screenshot appearing to show an Azure DevOps repository tied to an Accenture domain being cloned. Independent verification of the full dataset and its authenticity was not available at the time of reporting.
Accenture said it detected irregular activity, investigated the incident, contained the affected environment, remediated the source of the breach, and restored impacted systems. The company said operations and service delivery were not affected, but it has not disclosed how the intrusion occurred, how many systems or repositories were involved, whether the exposed credentials were valid, or whether any customer data or customer environments were impacted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Accenture acknowledged a cybersecurity incident and said it detected irregular activity, investigated the matter, contained the affected environment, and restored impacted systems. The company also said it remediated the source of the incident and that operations and service delivery were not impacted, while not confirming the full scope of any stolen data.
A threat actor using the name "888" claimed to have stolen and listed about 35 GB of Accenture data for sale on a cybercrime forum. The actor alleged the data included source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, and shared a screenshot appearing to show an Azure DevOps repository tied to an Accenture domain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcehipaajournal.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcesecuritymagazine.com
Open sourcecysecurity.news
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.