ctipilot.ch

888

actor · actor:888-extortion-handle

Financially motivated data-extortion/access-broker handle active on cybercrime forums since at least 2024, with a documented history of inflating breach-scope claims (a June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones); claimed a second Accenture data theft in July 2026 (~35 GB of source code, RSA/SSH keys and Azure PATs/storage keys from a private Azure DevOps repository).

Coverage timeline
2
first 2026-07-08 → last 2026-07-12
Peak priority
notable
2 notable
Sources cited
9
8 hosts
Sections touched
2
active-threats, weekly-incidents-recap
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
6
pinned v19.2 · see below
2026-07-082 appearances2026-07-12

ATT&CK techniques

6 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×2

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Story timeline

  1. 2026-07-12This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
    weekly-incidents-recapW28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig
  2. 2026-07-08Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials
    active-threatsAccenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure credentials

Where this entity is cited

  • active-threats1
  • weekly-incidents-recap1

Source distribution

  • bleepingcomputer.com2 (22%)
  • computing.co.uk1 (11%)
  • cybernews.com1 (11%)
  • helpnetsecurity.com1 (11%)
  • politie.nl1 (11%)
  • sec.gov1 (11%)
  • socradar.io1 (11%)
  • teiss.co.uk1 (11%)

explore in graph

Entries about 888 (2)

2026-07-12 · view entry permalink →

NOTABLENATOB1

This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim

Read as a set, the week's confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else's account, platform or supply chain.

The third-party / vendor strand: Accenture confirmed a data-theft incident after the handle "888" advertised roughly 35 GB of internal source code (BleepingComputer, 2026-07-08); Deutsche Bank disclosed a third-party-vendor incident after the "Unsafe" ransomware group posted claims (Computing, 2026-07-09); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (BleepingComputer, 2026-07-09). The cloud-account strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by "The Syndicate") in its own SEC Form 6-K (Nayax, 2026-07-09); ShinyHunters' Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (Politie, 2026-07-08); and Nextcloud GmbH's own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (Cybernews, 2026-07-10).

Why the pattern matters for the constituency: several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor's zero-day, a supplier's compromised account, or a misconfigured datastore in your own cloud footprint.

Builds on: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · 2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident · 2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update · 2026-07-09/nayax-cloud-account-incident-the-syndicate-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw

incident12 Jul 23:34Zmulti-sourceOpen finding ↗

2026-07-08 · view entry permalink →

NOTABLENATOB3

Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials

Accenture confirmed on 7 July 2026 that it suffered a data-theft incident after a threat actor using the handle "888" began advertising roughly 35 GB of internal data for sale on a cybercrime forum (BleepingComputer, 2026-07-07). Per the actor's own screenshots, the theft artefact shown is a request against a dev.azure.com endpoint followed by a git-clone of a private Azure DevOps repository named "121123_AtriasTalentAcademy" — an internal training/talent-academy project rather than confirmed client-delivery code — and the initial-access vector into that DevOps organisation has not been disclosed (teiss, 2026-07-08). The claimed dataset spans source code, RSA and SSH keys, Azure Personal Access Tokens and storage access keys — credential classes that, if valid and unrotated, chain into further Azure tenant / CI-CD compromise (T1078.004) or into downstream vulnerability discovery via the stolen source (T1213.003, T1552.001). Accenture's on-record statement confirms an incident but does not corroborate the actor's claimed scope, and SOCRadar explicitly flags that dataset authenticity, the 35 GB figure and key validity all remain unconfirmed (SOCRadar, 2026-07-08); "888" has a documented history of scope inflation (its June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones) (Help Net Security, 2026-07-08).

We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery.

Accenture spokesperson, via BleepingComputer

Several important details remain unclear: Whether the full advertised dataset is authentic, Whether the 35GB figure is accurate, Whether the alleged data is current, Whether any keys, tokens, or credentials are still valid.

SOCRadar 2026-07-08
incident08 Jul 20:35Zmulti-sourceOpen finding ↗