The real risk is not just source code loss. If the alleged bundle really includes Azure tokens and storage keys, a repo compromise can become standing access to cloud services and connected systems.
A threat actor using the name “888” says they stole just over 35GB from Accenture in July 2026 and is offering it for sale. The claimed haul includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, and a screenshot is being used as proof from a private Azure DevOps repository.
Accenture says it is aware of an isolated matter and has remediated the source, but it has not confirmed exfiltration. The open question is whether the theft is limited to code or includes secrets that keep working after the repository is cleaned up.