Accenture Confirms Data Breach as Hacker Sells Stolen Source Code
IT services giant Accenture confirms a security breach after a threat actor known as "888" claims to have stolen 35 GB of data from the company. The hacker begins offering the stolen data for sale on a cybercrime forum, advertising it as containing source codes taken during a July 2026 breach. Accenture tells BleepingComputer that the company is aware of the isolated matter and has already remediated its source, stating there is no impact to operations or service delivery.
According to the threat actor, the stolen data includes source code, RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. To support these claims, the hacker shares a screenshot that appears to show the cloning of an Azure DevOps repository hosted under an accenture.com hostname. BleepingComputer cannot independently verify the full scope of the stolen data, and Accenture declines to comment on the amount or type of data accessed.
Accenture does not disclose how attackers gained access or whether any customer data is affected. This is not the first security incident for the company, as the same threat actor previously attempts to sell Accenture employee data following a third-party breach in 2024. Accenture also suffers a separate data breach in 2021 when the LockBit ransomware gang steals data from its systems.