Accenture Suffers Massive Data Breach, Client Security Faces Potential Risks
Recently, a threat actor claiming to be "888" stated that they breached Accenture's systems in early July, stealing approximately 35GB of data, involving source code, Azure personal access tokens, RSA encryption keys, and SSH keys. An Accenture spokesperson stated that the issue has been fixed, but analysis by security firm SOCRadar indicates that the leaked source code and keys may expose Accenture and its clients to further attacks. This incident is not isolated, as Accenture previously suffered a LockBit ransomware attack and data exposure due to AWS misconfiguration.

A threat actor claimed to have stolen a large amount of sensitive data from consulting giant Accenture during a recent cyberattack. The hacker, who goes by the alias "888," stated in a dark web post that the leaked data includes source code, Microsoft Azure personal access tokens, RSA encryption keys, and SSH keys. This news was shared and reported by Bleeping Computer.
The actor claimed to have stolen approximately 35GB of data from Accenture during a breach in early July. Accenture downplayed the incident in a statement to Cybersecurity Dive.
"We are aware of this isolated incident and have remediated its source," spokesperson Peter Soh said. "Accenture's operations and service delivery have not been affected."
However, security experts warn that the stolen data could expose Accenture and its clients to significant further attack risks. Threat intelligence firm SOCRadar noted in an incident analysis: "Source code can help attackers understand internal application logic, identify weak implementation patterns, and search for hardcoded secrets or exploitable paths in custom systems." Meanwhile, exposed access keys could allow hackers to move freely within code repositories and cloud storage services.
Depending on the timeliness of the stolen data, this attack could have a ripple effect across Accenture's client base. SOCRadar analysts wrote: "Source code and configuration files could help attackers identify vulnerabilities in software used by clients or partners."
Accenture declined to answer follow-up questions regarding these potential consequences.
Part of a series of breaches
Accenture is one of the world's largest consulting firms, with a client list that includes the vast majority of Fortune Global 500 companies. But the company has also faced cybersecurity challenges in the past.
In 2021, the LockBit ransomware gang breached Accenture's systems and threatened to leak stolen data if a ransom was not paid. In 2017, security researchers at UpGuard disclosed that Accenture had misconfigured its Amazon Web Services (AWS) storage buckets, exposing sensitive data, including nearly 40,000 plaintext passwords and access keys for other cloud services.
The threat actor claiming responsibility for the latest incident used the same alias "888" as in 2024, when the hacker claimed to have stolen Accenture's massive employee database. At that time, Accenture stated that the hacker had greatly exaggerated the incident, and that the database contained information on only three of its employees.