On Monday 6 July 2026, a threat actor operating under the handle 888 posted on the cybercrime forum PwnForums, claiming to have breached Accenture, the global technology consulting and professional services company, and stolen just over 35 gigabytes of source code and associated credentials. Accenture confirmed the breach the following day, telling reporters it was aware of the isolated matter and had remediated its source. The company did not say how the attacker got in, and it did not dispute or confirm the scale of what 888 claims to hold.
According to 888's own forum post and the screenshot published alongside it, the entry point was a single compromised credential attached to an isolated, internet-facing network node. That credential opened a path into a restricted administrative repository: a private Azure DevOps project hosted on an accenture.com-associated production URL. From inside that repository, the attacker claims to have cloned out source code together with RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files, the exact material needed to move from one compromised repository into every system those keys touch.
This is not 888's first attempt against Accenture. In 2024, the same handle tried to sell data on 32,826 current and former employees, material Accenture later said contained only three genuine names and email addresses. This time the company has said far less: no dispute of the 35 gigabyte figure, no confirmation of it either, and no detail on which clients, projects, or downstream systems the exposed keys could reach.
Accenture has not put a figure on the damage, and it may not know the full scope yet. What is already public is enough to establish the risk. RSA keys, SSH keys, and cloud access tokens are not static documents; they are credentials that open other systems the moment someone uses them. This is the fourth publicly reported compromise of Accenture-held data since 2017, following exposed AWS storage buckets, a 2021 LockBit ransomware attack, and the 2024 employee data claim. Each has followed a similar shape: an entry point described as small, followed by data reaching further than the entry point ever suggested it would.
The defences that failed here were not weak by conventional standards. Accenture is one of the world's largest technology consultancies, building security programmes for its own clients as well as itself. The node the attacker used was reportedly isolated and internet-facing, precisely the kind of asset that gets segmented, monitored, and patched under a mature security programme. None of that mattered once a valid credential opened the repository sitting behind it. The controls in place governed who could reach the node. Nothing governed what happened at the moment its contents were pulled out.
A private repository holding RSA keys, SSH keys, and cloud access tokens is not a passive filing cabinet. Cloning it out in bulk is an execution event, the single action that turns a contained credential compromise into an exposed supply chain. Before that export can complete, GoFirm sends a real-time push notification to the named authority responsible for that repository, on their registered device, requiring biometric confirmation. No confirmation, no export. It makes no difference whether the request arrives on a valid session token, a compromised service account, or a credential lifted from a node three hops away.
A stolen Azure personal access token, however valid it appears to every system checking it, cannot produce a biometric confirmation on a device it does not control. The execution boundary holds regardless of how legitimate the credential looks to everything else in the chain.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
1. Abrams, L. 2026. Accenture confirms breach after hacker offers stolen data for sale. BleepingComputer, 7 July 2026.
2. Zorz, Z. 2026. Accenture acknowledges security incident following 35GB data theft claim. Help Net Security, 8 July 2026.
Back to Blog
Case Studies·3 min read
Accenture called it an isolated matter. A hacker was already selling the keys.
By GoFirm
