Update (July 8, 2026): Following publication of this article, Accenture confirmed it is aware of what it described as an “isolated matter.” In a statement provided to Help Net Security, the company said it had “remediated its source” and that the incident did not affect its operations or service delivery. However, Accenture did not confirm whether data had been exfiltrated or provide additional details about the nature of the incident.
While the company’s statement does not verify the threat actor’s claims regarding the alleged theft of source code or cloud credentials, it does confirm that Accenture investigated a security incident related to the matter.
Consulting and technology giant Accenture has acknowledged an isolated security incident after a cybercrime forum listing alleged the theft of approximately 35 GB of internal source code and cloud infrastructure data. While the company confirmed it investigated the incident, it has not verified the alleged scope of the claimed data theft.
According to the listing, the alleged archive contains source code, RSA private keys, SSH keys, Azure Personal Access Tokens (PATs), Azure Storage access keys, and configuration files. The seller describes the offering as a one-time sale but does not disclose how the alleged data was obtained.
Forum post claims access to private Azure DevOps repository
The forum listing includes a screenshot purporting to show access to a private Azure DevOps repository associated with an Accenture project. The screenshot appears to display repository metadata and a successful clone operation from what is claimed to be a private development environment.
BreachNews reviewed the screenshot but could not independently verify that the files allegedly offered for sale originated from the repository shown or confirm the scope of any data that may have been accessed or exfiltrated.
The seller also references an alleged archive size of just over 35 GB and claims it contains internal development assets rather than customer records.
Source code and cloud secrets reportedly included
According to the forum listing, the alleged dataset includes:
- Source code repositories
- RSA private keys
- SSH keys
- Azure Personal Access Tokens (PATs)
- Azure Storage access keys
- Configuration files
If authentic, exposure of source code together with cloud credentials could present a greater security risk than source code alone. Credentials and infrastructure secrets may provide attackers with insight into development environments, deployment pipelines, or cloud resources if they remain valid.
The forum post does not include technical details describing how the alleged compromise occurred or whether any credentials shown have since been revoked.
Authenticity of the listing is unclear
Accenture has acknowledged an isolated security incident but has not confirmed the alleged theft of source code, cloud credentials, or any other data referenced in the forum listing.
Although Accenture has acknowledged a security incident, the authenticity, scope, and origin of the claimed dataset remain unverified. While the company said it remediated the source of the incident, it did not disclose whether any data was exfiltrated or provide additional technical details about the event.
This is not the first time Accenture has been linked to a cybersecurity incident. In 2021, the company disclosed a ransomware attack after the LockBit group claimed responsibility and threatened to publish allegedly stolen data. In 2024, a threat actor also attempted to sell what was purported to be employee data associated with Accenture following an alleged third-party breach, though the company said the dataset contained only a limited amount of Accenture information.
Why attackers pursue developer infrastructure
Source code repositories and cloud development environments continue to be frequent targets for cybercriminals because they can contain proprietary intellectual property, infrastructure configurations, authentication material, and deployment secrets. Access to developer platforms may also provide opportunities for supply chain attacks or further compromise of enterprise environments.
Recent BreachNews coverage involving alleged source code and developer environment exposures includes the alleged Darsa AI source code and cloud data leak, the alleged AstraZeneca source code and cloud credentials leak, and the alleged Radisys source code breach.












