A hacker put 35GB of a consulting giant's source code, signing keys, and cloud tokens up for sale

The company confirmed the breach and called it "isolated." It did not say what was actually taken.
Accenture, July 6 — a threat actor using the handle "888" claimed to have stolen source code, RSA keys, SSH keys, Azure Personal Access Tokens, Azure Storage access keys, and configuration files, backed by a screenshot of a cloned internal Azure DevOps repository.
WHAT ACTUALLY HAPPENED
The seller's proof included a repository named after an internal project, hosted under a censored accenture.com domain — the kind of detail that is hard to fabricate convincingly. Accenture's response: "We are aware of this isolated matter and we have remediated its source. There is no impact to Accenture operations and service delivery." The company confirmed an intrusion occurred but did not comment on the scope, volume, or type of data the attacker claims to hold.
WHY "NO IMPACT TO OPERATIONS" ISN'T THE QUESTION THAT MATTERS
Accenture doesn't just run its own infrastructure — it builds and manages systems inside client environments across finance, government, and healthcare. Source code reveals internal application logic and can expose hardcoded secrets. Cloud access keys and signing material, if genuine, are not an Accenture-only problem — they are a problem for every environment those credentials touch. "No impact to our operations" says nothing about impact to the systems Accenture manages on behalf of someone else.
WHAT TO DO NOW
IF ACCENTURE TOUCHES YOUR ENVIRONMENT, ASK FOR SPECIFICS — a reassurance statement is not a scope assessment; request confirmation your tenant, keys, or code were not involved.
ROTATE ANY SHARED CREDENTIALS ISSUED TO OR BY ACCENTURE CONTRACTORS — treat this as a precaution regardless of what the company has confirmed.
WATCH FOR SOURCE-CODE-DERIVED ATTACKS IN THE COMING MONTHS — stolen source code fuels targeted exploitation long after the initial breach headline fades.
DO NOT ACCEPT "ISOLATED MATTER" AS A COMPLETED RISK ASSESSMENT — that is a public relations characterization, not an audit finding.
A vendor's confidence in their own remediation is not evidence your exposure ended where theirs did.
If a major consultancy or MSP touching your environment had a breach tomorrow, do you know exactly which of your credentials and systems they can reach?