Accenture says it suffered a security breach after a threat actor began selling allegedly stolen company data online. The actor known as "888" claims to have taken about 35 GB of data in July 2026, including source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, and shared a screenshot purporting to show an Azure DevOps repository cloned from an Accenture-hosted system. Accenture called it an isolated incident and said it remediated the source, but did not disclose the intrusion method or whether customer data was affected.
Why it matters: Stolen source code and cloud or administrator keys can create follow-on risk well beyond the initial breach, including unauthorized access to internal systems or customer-connected environments. Organizations that work with Accenture should watch for advisories, rotate exposed credentials if notified, and review any trust relationships or shared access.
Ionut Arghire
2026.07.08
99% relevant
This article is a direct report on the same incident, adding that Accenture confirmed the breach, said it remediated the source of the compromise, and stated there was no operational or service delivery impact while the attacker claimed theft of 35 GB including Azure keys, tokens, SSH/RSA keys, config files, and source code.
Lawrence Abrams
2026.07.07
100% relevant
This article appears to be the first clear reporting of a newly confirmed 2026 Accenture breach tied to a threat actor's sale of allegedly stolen internal data.
← Back to all stories