Overview
- This week Accenture told reporters it was aware of an isolated security matter, said it has remediated the source, and asserted there is no impact to operations or service delivery.
- A forum user calling themselves "888" posted an offer to sell roughly 35 GB of Accenture source code and related secrets and shared a screenshot that appears to show cloning of an Azure DevOps repository.
- Accenture declined to confirm how the alleged data was taken, what exact files or credentials were exposed, or whether any customer or personal data was affected.
- Security experts note that claimed artifacts such as RSA/SSH keys, Azure personal access tokens, and storage keys could let attackers move laterally, impersonate services, or access connected cloud resources if the items are valid.
- The report follows past Accenture exposures including 2017 unsecured S3 buckets and a 2021 LockBit-related theft, and investigators will be looking for independent verification of the forum evidence and any customer notices or mitigations.