A Seller Claims to Have 35GB of Accenture Data, Including Source Code and Keys
Key takeaways
- An actor using the name 888 claims to be selling 35GB of data taken from Accenture, said to include source code and access keys.
- The claim is unverified, but the pattern is familiar: breaching a large services firm is a route into its clients.
- Rotate credentials shared with vendors and audit what third party access still exists in your environment.
A listing has appeared advertising 35GB of data said to have been taken from Accenture, posted by an actor going by 888. The claimed contents are the part worth reading twice: source code and access keys. Nothing here is confirmed, and claims on these forums are routinely inflated or recycled from old breaches, so treat the specifics with suspicion.
The shape of the risk is not in doubt though. When a large consulting or managed services firm is breached, the firm itself is rarely the prize. Its clients are. A services company holds credentials, repositories and remote access into hundreds of other organisations, which makes one successful intrusion into a key ring rather than a single door.
Notice also what is missing from this incident. There is no ransomware, no encrypted estate, no countdown timer. Just quiet resale to whoever wants it. That model is harder to spot and harder to price, because the damage arrives later and somewhere else, in an environment that was never itself attacked.
The practical response does not depend on whether this particular claim holds up. Rotate credentials that are shared with vendors, expire long lived access tokens, and pull a list of every third party that still has a route into your systems. Most organisations find at least one entry on that list that should have been closed a year ago.