AIO APEX

Accenture confirms breach after hacker claims 35GB source code and Azure key theft

BleepingComputer
Share:
Accenture confirms breach after hacker claims 35GB source code and Azure key theft

Accenture has confirmed a security breach after a threat actor known as "888" posted stolen data on a cybercrime forum, claiming to have exfiltrated 35GB of material including source code, cryptographic keys, and Azure cloud access credentials. The consulting giant acknowledged the incident while providing few specifics about what was taken or whether client projects were affected.

What was stolen

The threat actor published proof of access on PwnForums — a screenshot demonstrating successful cloning of a private Azure DevOps repository hosted on an Accenture domain. The claimed haul includes source code, RSA keys, SSH keys, Azure Personal Access Tokens (PAT), Azure Storage access keys, and configuration files, running to approximately 35GB in total.

Azure Personal Access Tokens are particularly dangerous if not rotated immediately after discovery. They can grant ongoing access to code repositories and build pipelines long after the initial breach is contained. In Accenture's environment — which supports banks, defense contractors, and government agencies worldwide — unrevoked tokens represent a second wave of exposure that depends entirely on how quickly the company identified and rotated every affected credential.

Accenture's response

The company confirmed the incident with a minimal statement: "We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery."

Accenture did not confirm or deny whether client data was among the stolen files, did not say how the attacker gained access to the Azure DevOps environment, and gave no indication of when the breach occurred or how long access persisted before discovery.

How credible is the claim?

The same threat actor, "888," claimed to hold data on tens of thousands of Accenture employees in 2024. That cache turned out to contain only three names and email addresses — a significant mismatch between the claim and reality. This incident is harder to dismiss on those grounds. Accenture itself acknowledged a breach rather than denying the claim, the Azure DevOps screenshot is specific and technically coherent, and the combination of access keys, SSH keys, and source code represents a realistic and dangerous result from a single compromised cloud repository.

The data types alleged also matter more than volume. Source code alone is valuable to competitors or state actors. Paired with Azure PATs and SSH keys, the same access could theoretically reach live infrastructure if Accenture's credential rotation was incomplete or delayed.

Client exposure risk

Accenture serves some of the world's largest banks, defense agencies, and governments, often maintaining dedicated delivery environments for client projects. The company's statement covers its own operations and service delivery — it makes no representation about whether any stolen source code or credentials relate to client-specific systems rather than Accenture's internal tooling. That distinction is precisely what clients, regulators, and the security community will want answered.

The incident was first reported by BleepingComputer.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: