2026-07-08NOTABLEAccenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure credentials
888
actor · actor:888-extortion-handle
Financially motivated data-extortion/access-broker handle active on cybercrime forums since at least 2024, with a documented history of inflating breach-scope claims (a June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones); claimed a second Accenture data theft in July 2026 (~35 GB of source code, RSA/SSH keys and Azure PATs/storage keys from a private Azure DevOps repository).
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Accenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector
Sources cited
4
4 hosts
Action items (2)
Do-now tasks recorded on the entries about 888, newest first. Check the date before acting on an older one.
- Organisations running Azure DevOps: audit repository clone/download volume and clones from unfamiliar egress IPs/ASNs; monitor Entra ID sign-in logs for PAT-authenticated Azure Resource Manager / DevOps REST calls from unusual geolocations or impossible-travel.2026-07-08Accenture confirms a data-theft incident; '888'…
- Rotate long-lived Azure DevOps PATs and storage access keys to short-lived Entra Workload Identity Federation / OIDC tokens; run Advanced Security secret scanning + push protection across all repos; enforce IP-restricted Conditional Access on the DevOps organization.2026-07-08Accenture confirms a data-theft incident; '888'…
Defender insights
What each entry about 888 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (3 across 6 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Cloud Accounts
- PersistenceValid Accounts: Cloud Accounts
- Privilege EscalationValid Accounts: Cloud Accounts
- StealthValid Accounts: Cloud Accounts
- Credential AccessUnsecured Credentials: Credentials In Files
- CollectionData from Information Repositories: Code Repositories
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Collection TA0009
T1213.003Data from Information Repositories: Code Repositories×1
Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.
Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗
Entries about 888 (1)
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (25%)
- helpnetsecurity.com1 (25%)
- socradar.io1 (25%)
- teiss.co.uk1 (25%)
All cited sources (4)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/07/08/accenture-data-breach-2026/
- socradar.ioSOCRadarhttps://socradar.io/blog/accenture-breach-claim-35gb-data-stolen/
- teiss.co.ukteisshttps://www.teiss.co.uk/news/accenture-confirms-security-breach-as-hacker-claims-theft-of-35-gb-of-source-code-17789