Accenture confirms security incident after hacker 888 offers 35 GB of allegedly stolen source code and Azure credentials for sale
Every company with code in Accenture $ACN pipelines got a new worry: a hacker known as 888 is selling 35 GB allegedly taken from the firm's Azure DevOps repos, including source code, RSA keys and access tokens. Accenture calls it an isolated, remediated matter. Per BleepingComput
Accenture $ACN, the global IT consultancy, has confirmed a security incident after a hacker known as 888 offered stolen data for sale on a cybercrime forum. The seller claims 35 GB of material taken from Accenture's Azure DevOps repositories: source code, RSA keys, SSH keys, Azure Personal Access Tokens, storage access keys and configuration files. To back the claim, the actor posted a screenshot of a live git clone from a repository under an accenture.com domain. Accenture told BleepingComputer it is aware of the matter, has remediated its source, and sees no impact on operations or service delivery. The company did not say how the breach happened or whether client data was affected. That last gap is the real issue. Access tokens and storage keys are live credentials, not just leaked files. For the enterprises whose development pipelines run through Accenture, the relevant question is whether anything client-facing sat in the affected repositories, and the public statement does not answer it. Reported by BleepingComputer and Help Net Security.