{"id":62456,"date":"2026-07-08T02:14:21","date_gmt":"2026-07-08T06:14:21","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62456"},"modified":"2026-08-31T03:27:23","modified_gmt":"2026-08-31T07:27:23","slug":"accenture-breach-source-code-stolen-62456","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/accenture-breach-source-code-stolen-62456\/","title":{"rendered":"Accenture Confirms Breach, Hacker Sells 35GB Source Code"},"content":{"rendered":"<p>IT services and consulting giant <a href=\"https:\/\/www.accenture.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Accenture<\/a> has confirmed that it suffered a security <a href=\"https:\/\/overcentral.com\/en\/uber-freight-data-breach\/\" title=\"Uber Freight Probes Data Breach After Hackers Claim Attack\" data-iacss-internal=\"1\">breach after<\/a> a threat actor claimed to have stolen approximately 35 GB of source code and internal data from the company. The breach, which the threat actor alleges occurred in July, has already led to an attempt to sell the stolen data on a cybercrime forum. Accenture issued a statement acknowledging the incident, describing it as an &#8220;isolated matter&#8221; that has been remediated, and stated that operations and service delivery have not been impacted.<\/p>\n<p>Accenture, a global professional services firm providing consulting, technology, cloud, engineering, and managed services to businesses and governments worldwide, did not disclose the specific entry point used by the attackers or confirm whether customer data was among the exfiltrated materials. The company also did not comment on the exact volume or type of data that may have been accessed.<\/p>\n<h2>Threat Actor Claims Theft of Source Code and Access Credentials<\/h2>\n<p>According to the threat actor, who operates under the alias &#8220;888,&#8221; the stolen data includes source code, RSA keys, SSH keys, Azure Personal Access Tokens, Azure Storage access keys, and configuration files. The actor posted on a cybercrime forum, stating: &#8220;In July 2026, Accenture suffered a data breach which resulted in just over 35GB of source codes getting stolen from the company.&#8221; As evidence, the actor shared a screenshot showing the cloning of an Azure DevOps repository named &#8220;121123_AtriasTalentAcademy&#8221; hosted under a redacted accenture.com hostname. BleepingComputer was unable to independently verify the full scope <a href=\"https:\/\/overcentral.com\/en\/servant-of-the-lake-achievement-guide\/\" title=\"Servant Of The Lake Unlocks Every Achievement\" data-iacss-internal=\"1\">of the<\/a> data claimed to be stolen.<\/p>\n<h2>Accenture&#8217;s Prior Cybersecurity Incidents<\/h2>\n<p>This is not the first time Accenture has faced a significant cyber incident. In 2021, the LockBit ransomware gang successfully breached Accenture&#8217;s systems and exfiltrated data. Additionally, in 2024, the same threat actor now claiming responsibility for this breach had previously attempted to sell what they described as Accenture employee data, which was reportedly obtained through a third-party breach. These recurring incidents highlight the persistent targeting of large IT services providers, which hold vast amounts of sensitive data and code for numerous clients.<\/p>\n<h2>What Affected Users and Organizations Should Do Now<\/h2>\n<p>While Accenture has stated that operations and service delivery remain unaffected, the exposure of sensitive credentials, including Azure PATs and storage access keys, presents a significant risk. Organizations that partner with or rely on Accenture-managed systems should immediately review any shared credentials or tokens and rotate them as a precautionary measure. Affected individuals, particularly those whose employee data may have been compromised in prior incidents, should enable multi-factor authentication on all accounts, monitor for phishing attempts and account takeover attempts, and use strong, unique passwords managed through a zero-knowledge password manager. For any organization using Azure DevOps or cloud infrastructure, this incident serves as a critical reminder to audit and rotate all personal access tokens and service principal credentials regularly, especially those with broad permissions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT services and consulting giant Accenture has confirmed that it suffered a security breach after a threat actor claimed to have stolen approximately 35 GB of source code and internal data from the company. The breach, which the threat actor alleges occurred in July, has already led to an attempt to sell the stolen data [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74406,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/ClTF78G.jpg","fifu_image_alt":"Accenture Confirms Breach, Hacker Sells 35GB Source Code","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62456","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/ClTF78G.jpg","fifu_image_alt":"Accenture Confirms Breach, Hacker Sells 35GB Source Code","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62456"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62456\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74406"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}