Accenture Confirms Breach After Hacker Offers 35 GB of Source Code, Keys, and Config Files for Sale
What Happened — A threat actor identified as “888” posted on a cyber‑crime forum claiming to have exfiltrated roughly 35 GB of Accenture data, including proprietary source code, RSA/SSH keys, Azure personal access tokens, storage access keys, and configuration files. Accenture acknowledged an “isolated matter,” says it has remediated the source, and reports no impact to operations or service delivery.
Why It Matters for Compliance & Audit Readiness
- The incident highlights the need for SOC 2‑aligned access‑control policies that protect privileged credentials (CC6.1 – Logical Access Controls).
- Continuous evidence of key‑management practices (rotation, revocation, monitoring) is essential to demonstrate due diligence during a SOC 2 audit.
- Mapping this breach to your control framework provides a defensible audit trail and helps close gaps before regulators or customers inquire.
Who Is Affected — Global professional‑services firms, managed‑service providers, and their downstream customers that rely on shared development environments (e.g., Azure DevOps).
Recommended Actions
- Immediately rotate all exposed RSA/SSH keys, Azure PATs, and storage access keys; enforce MFA on privileged accounts.
- Conduct a SOC 2 access‑control gap analysis (CC6.1, CC6.2) and capture evidence of remediation for audit purposes.
- Implement continuous monitoring of credential usage and DevOps repository activity, logging all privileged actions.
- Update incident‑response playbooks to include credential‑compromise scenarios and test them with breach‑simulation exercises.
Source: BleepingComputer
Technical Notes
- Attack vector appears to involve stolen credentials (Azure DevOps PATs, SSH keys) enabling cloning of a private repository.
- No specific CVE disclosed; the breach is attributed to credential compromise and possible mis‑configuration of secret storage.
- Data types: source code, RSA keys, SSH keys, Azure PATs, Azure storage access keys, configuration files.