Overview
- A threat actor using the handle "888" posted on PwnForums in early July 2026 claiming to sell just over 35 GB of Accenture data, including source code, RSA/SSH keys, Azure personal access tokens, storage keys and configuration files.
- Accenture told reporters it is "aware of this isolated matter," has remediated its source and that operations and service delivery were not impacted, but the company declined to disclose technical details or the scope of any exfiltration.
- Multiple security outlets noted the actor supplied a screenshot showing cloning of an Azure DevOps repo that appears to be tied to an accenture.com hostname, but independent verification of the archive's contents is lacking.
- Security experts warn that stolen source code, keys and tokens can serve as a blueprint for follow‑on intrusions because they reveal system architecture, authentication methods and reusable credentials.
- The listing follows a pattern of repeat targeting: the same handle previously tried to sell Accenture employee data in 2024 and Accenture has faced notable incidents such as the LockBit breach in 2021, which keeps clients and security teams on alert.