Accenture confirms break-in as hacker offers 35GB of stolen code for sale
The consulting giant says the incident is contained, but a forum seller known as 888 claims to be holding source code, Azure access keys and SSH keys taken in July 2026.

Key points
- Accenture confirmed on the record that it suffered a security incident after a hacker known as 888 advertised stolen data for sale.
- The seller claims to hold 35GB of source code taken from Accenture in July 2026.
- The listing also mentions RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys and configuration files.
- Accenture says the source has been fixed and there is no impact to operations or client service delivery.
- The same seller previously touted Accenture employee data in 2024, and the company was hit by the LockBit ransomware crew in 2021.
Accenture, one of the world's largest IT consulting firms, has confirmed a security breach after a hacker put what they say is stolen company data up for sale on a cybercrime forum.
"We are aware of this isolated matter, and we have remediated its source," the company told BleepingComputer, which first reported the confirmation. "There is no impact to Accenture operations and service delivery."
The seller uses the handle 888. Their forum post claims they took just over 35 gigabytes of source code from Accenture in July 2026, alongside RSA and SSH keys (the digital credentials that servers and developers use to prove identity), Azure personal access tokens (login codes for Microsoft's cloud), Azure Storage access keys and configuration files.
To back up the claim, 888 posted a screenshot that appears to show them cloning an internal Accenture code repository called "121123_AtriasTalentAcademy", hosted on an Azure DevOps address ending in accenture.com. The full scope of what was taken hasn't been independently verified.
Accenture hasn't said how the attackers got in, how much data left its systems, or whether any client information was involved.
Is this a nation-state operation?
Almost certainly not. The activity looks like straightforward financially motivated crime, not espionage.
888 is a forum persona tracked as a serial data broker. No public reporting from Mandiant, CrowdStrike or Microsoft links the handle to a named intrusion cluster, and no overlapping infrastructure or tradecraft ties it to groups like Kimsuky or Sandworm. Treat any attribution beyond "forum-based data seller" as low confidence.
Capability and intent are different things. A broker who ends up with source code and cloud keys is dangerous regardless of pedigree. Leaked Azure tokens and SSH keys can be reused to log straight back into systems, or sold on to a ransomware affiliate.
What could actually be in the files?
Source code from a firm like Accenture isn't just Accenture's problem. The company builds and runs software for banks, governments and insurers, so its repositories often contain client project code, internal tools and, in the worst case, hard-coded secrets that reach into client systems.
Cloud access keys are the bigger short-term worry. If any of the Azure tokens listed by 888 are still live, whoever buys them could read cloud storage, pivot into build pipelines, or plant malicious changes in code flowing downstream to customers. This is the same style of supply-chain risk that made the SolarWinds intrusion so damaging. The Azure CLI password-spray campaign we reported on 1 July, which hit 78 tenants across two weeks, is a reminder of how quickly exposed cloud credentials get weaponised.
Accenture says it has "remediated the source", meaning the entry point has been closed and exposed credentials rotated. It doesn't tell us whether copies of the data are already circulating.
Should you worry if you're an Accenture customer?
Yes, if your organisation uses Accenture for development or managed services. Find out which of your systems Accenture holds credentials for, and confirm those credentials have been rotated recently. Any shared API tokens or service accounts tied to Accenture-run projects should be treated as potentially exposed until the company says otherwise.
This isn't Accenture's first difficult period. LockBit stole data from the firm in 2021, and 888 surfaced Accenture employee records in 2024 through a third-party breach. For a company that announced a $4.1 billion push into OT security in June, a breach involving its own developer infrastructure is an uncomfortable reminder that the hardest systems to secure are often your own.
The pattern here isn't attribution to any one crew. It's that a firm this size, handling this much client infrastructure, keeps appearing in the same forums.



