Accenture Confirms Breach After Hacker Claims 35 GB of Stolen Data

Accenture confirmed it was hit by a security breach after a threat actor started selling what they claim is 35 GB of stolen company data on a cybercrime forum.

“We are aware of this isolated matter, and we have remediated its source,” Accenture told BleepingComputer. “There is no impact to Accenture operations and service delivery.”

The threat actor, going by “888,” posted the data for sale in July. According to the forum listing, the stolen cache includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. To back up the claims, they shared a screenshot showing them cloning an Azure DevOps repository under an accenture.com hostname.

Accenture didn’t confirm the specific types or volume of data taken. They also didn’t say how attackers got in or whether any customer data was affected.

This isn’t the first time. Accenture was hit by LockBit ransomware in 2021, and the same attacker “888” previously tried to sell Accenture employee data after a third-party breach in 2024.

The public confirmation came only after the stolen data was being actively shopped around. That’s a pattern we’ve seen before — companies confirm breaches only once the data’s already for sale.

If you’re an Accenture client, it’s worth asking what systems were actually accessed. The company says operations aren’t impacted, but stolen source code and access keys can have long tails.