Accenture confirms breach after hacker offers stolen data for sale

Global IT Services Giant Accenture Hit by Security Breach, Hacker Offers Stolen Data for Sale

Accenture, one of the world’s largest professional services companies, has confirmed that it was the target of a security breach. A hacker, known as “888,” claims to have stolen 35 GB of sensitive data from the company and is now offering it for sale on a cybercrime forum.

The stolen data includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. To support their claims, the hacker shared a screenshot showing them cloning an Azure DevOps repository hosted under an Accenture hostname. However, the extent of the breach is still unclear, as Accenture has not commented on the threat actor’s specific allegations.

Accenture provides consulting, technology, cloud, engineering, and managed services to businesses and governments worldwide. The company’s operations are not impacted by the breach, according to a statement issued by Accenture. However, it remains uncertain whether customer data was affected by the incident.

This is not Accenture’s first brush with cybercrime. In 2021, the LockBit ransomware gang stole data from its systems, and in 2024, the same hacker attempted to sell Accenture employee data following a third-party breach. The latest breach raises concerns about the company’s cybersecurity measures and whether they can prevent such incidents in the future.

The incident also highlights the growing threat of cybercrime forums where stolen data is being bought and sold. These platforms provide a haven for hackers to monetize their ill-gotten gains, making it difficult for companies like Accenture to contain the damage caused by security breaches.

Accenture’s response to the breach has been limited so far, with the company failing to comment on how attackers gained access or whether customer data was compromised. The lack of transparency raises questions about the company’s commitment to cybersecurity and its ability to protect sensitive information.

The incident is a reminder that companies must prioritize cybersecurity and invest in robust measures to prevent such breaches from happening. It also underscores the importance of vigilance in detecting and responding to security threats. As Accenture continues to navigate this crisis, it will be crucial for the company to provide more information about the breach and its plans to mitigate any potential harm.

For individuals and organizations, this incident serves as a timely reminder to stay vigilant and take proactive steps to protect themselves from cyber threats. By regularly testing their defenses and staying informed about emerging security risks, they can minimize their exposure to attacks like these.


Source: Bleeping Computer — 2026-07-07