Accenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys
Accenture has confirmed it suffered a data breach after a threat actor turned up on PwnForums this week claiming to have walked off with 35 gigabytes of the firm's internal data.
The hacker's shopping list allegedly includes Azure access keys and tokens, RSA and SSH keys, configuration files, and source code. As a credibility flex, they posted a screenshot of what appeared to be a private Azure DevOps repository sitting on an accenture.com domain. They were also trying to sell the lot.
Accenture's official response was about as informative as you'd expect. A spokesperson told SecurityWeek: "We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery." No detail on how the attacker got in, what exactly was taken, or whether any personal data was caught up in it.
The company is keeping its cards close, which is understandable from a legal and reputational standpoint, but leaves a lot of questions hanging. How did someone get into an Azure DevOps environment? Were credentials phished, bought, or brute-forced? Unknown.
Ross Filipek, CISO at Corsica Technologies, pointed out the obvious problem with this kind of breach: even if nothing blows up immediately, stolen source code and infrastructure credentials become a manual for future attacks. Attackers can comb through codebases for vulnerabilities, extract hardcoded secrets, and map out how the environment is wired together.
The deeper concern is where Accenture sits in the enterprise food chain. Big consulting and services firms are routinely embedded in their clients' most sensitive systems, from cloud migrations to identity infrastructure. A foothold at a firm like Accenture doesn't just expose Accenture. It potentially offers a window into how a dozen enterprise clients have built and secured their own environments.
This isn't Accenture's first awkward headline. The company recently announced a majority stake in industrial cybersecurity firm Dragos, and last year confirmed that a former employee had been charged with concealing compliance failures in cloud products sold to the US government.
Make of that track record what you will.