CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

888

actor · actor:888-extortion-handle

Financially motivated data-extortion/access-broker handle active on cybercrime forums since at least 2024, with a documented history of inflating breach-scope claims (a June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones); claimed a second Accenture data theft in July 2026 (~35 GB of source code, RSA/SSH keys and Azure PATs/storage keys from a private Azure DevOps repository).

Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
Accenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector
Sources cited
4
4 hosts

Action items (2)

Do-now tasks recorded on the entries about 888, newest first. Check the date before acting on an older one.

  • Organisations running Azure DevOps: audit repository clone/download volume and clones from unfamiliar egress IPs/ASNs; monitor Entra ID sign-in logs for PAT-authenticated Azure Resource Manager / DevOps REST calls from unusual geolocations or impossible-travel.
    2026-07-08Accenture confirms a data-theft incident; '888'…
  • Rotate long-lived Azure DevOps PATs and storage access keys to short-lived Entra Workload Identity Federation / OIDC tokens; run Advanced Security secret scanning + push protection across all repos; enforce IP-restricted Conditional Access on the DevOps organization.
    2026-07-08Accenture confirms a data-theft incident; '888'…

Defender insights

What each entry about 888 tells a defender to do, newest first.

2026-07-08NOTABLEAccenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure credentials

Story timeline

  1. 2026-07-08Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials
    active-threatsAccenture confirms a data-theft incident; '888' claims 35 GB of source code, RSA/SSH keys and Azure credentials
ATT&CK techniques (3 across 6 tactics)

3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts: Cloud Accounts
  • PersistenceValid Accounts: Cloud Accounts
  • Privilege EscalationValid Accounts: Cloud Accounts
  • StealthValid Accounts: Cloud Accounts
  • Credential AccessUnsecured Credentials: Credentials In Files
  • CollectionData from Information Repositories: Code Repositories

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · ATT&CK page ↗

Entries about 888 (1)

2026-07-08 · view entry permalink →

NOTABLENATOB3

Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials

Accenture confirmed on 7 July 2026 that it suffered a data-theft incident after a threat actor using the handle "888" began advertising roughly 35 GB of internal data for sale on a cybercrime forum (BleepingComputer, 2026-07-07). Per the actor's own screenshots, the theft artefact shown is a request against a dev.azure.com endpoint followed by a git-clone of a private Azure DevOps repository named "121123_AtriasTalentAcademy" (an internal training/talent-academy project rather than confirmed client-delivery code) and the initial-access vector into that DevOps organisation has not been disclosed (teiss, 2026-07-08). The claimed dataset spans source code, RSA and SSH keys, Azure Personal Access Tokens and storage access keys, credential classes that, if valid and unrotated, chain into further Azure tenant / CI-CD compromise (T1078.004) or into downstream vulnerability discovery via the stolen source (T1213.003, T1552.001). Accenture's on-record statement confirms an incident but does not corroborate the actor's claimed scope, and SOCRadar explicitly flags that dataset authenticity, the 35 GB figure and key validity all remain unconfirmed (SOCRadar, 2026-07-08); "888" has a documented history of scope inflation (its June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones) (Help Net Security, 2026-07-08).

We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery.

Accenture spokesperson, via BleepingComputer

Several important details remain unclear: Whether the full advertised dataset is authentic, Whether the 35GB figure is accurate, Whether the alleged data is current, Whether any keys, tokens, or credentials are still valid.

SOCRadar 2026-07-08
incident08 Jul 20:35Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • bleepingcomputer.com1 (25%)
  • helpnetsecurity.com1 (25%)
  • socradar.io1 (25%)
  • teiss.co.uk1 (25%)