Breaches · 68 days ago
The real risk is not just source code loss. If the alleged bundle really includes Azure tokens and storage keys, a repo compromise can become standing access to cloud services and connected systems.
A threat actor using the name “888” says they stole just over 35GB from Accenture in July 2026 and is offering it for sale. The claimed haul includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, and a screenshot is being used as proof from a private Azure DevOps repository.
Accenture says it is aware of an isolated matter and has remediated the source, but it has not confirmed exfiltration. The open question is whether the theft is limited to code or includes secrets that keep working after the repository is cleaned up.
3 sources covering this story
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
The professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact.
Accenture acknowledges security incident following 35GB data theft claim - Help Net Security
Technology consulting company Accenture appears to have suffered a data breach, the extent of which is currently unknown.
Accenture confirms breach after hacker offers stolen data for sale
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company.
Part of the PlainSec briefing for 2026-07-09