There’s a special kind of schadenfreude reserved for watching a security consultancy get owned by Security 101. This week it was Accenture’s turn.
A threat actor going by “888” — a handle with previous, mostly unimpressive form against the company — popped up on the cybercrime forum PwnForums claiming to have lifted “just over 35gb” of Accenture’s source code, plus a grab-bag of the stuff that should never leave a vault: RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. As proof, they posted a screenshot showing exfiltration from a private Azure DevOps repo tied to an accenture.com production URL.
Accenture’s response was the corporate equivalent of stepping over a puddle without acknowledging it’s raining: “aware of this isolated matter,” source “remediated,” no impact to operations, no confirmation of what was actually taken.
Governments and boardrooms spend fortunes on firms whose whole pitch is “we’ll audit your posture.” Turns out the audit doesn’t always start at home.
Here’s the part that should needle anyone who’s run a CI/CD pipeline: none of the alleged haul is exotic. It’s not a zero-day, not some nation-state supply-chain masterstroke. If the claims hold up, it’s the oldest story in DevOps — long-lived tokens and keys sitting in a repo where a compromised credential or a leaked config file was enough to walk out the door with the crown jewels. Accenture’s entire commercial pitch to clients is “we’ll help you not do this.” The gap between the brochure and the breach report is where the comedy lives.
For anyone running production systems — including a one-person shop wiring together a Python/ffmpeg pipeline with API keys scattered across a CSV-driven batch job — the actual lesson isn’t “don’t get hacked, lol.” It’s that access tokens, SSH keys and API secrets need to live somewhere that isn’t a config file or a Slack DM, with rotation and audit trails, not vibes.
The fix for this exact failure mode is boring on purpose: shared, encrypted, audited storage for team credentials — API keys, SSH keys, access tokens — instead of everyone pasting secrets into a repo, a spreadsheet, or Notion. NordPass Business (and the wider secrets-vaulting category it sits in) is built for precisely this.
มีความสะใจแบบพิเศษที่สงวนไว้สำหรับการได้เห็นบริษัทที่ปรึกษาด้านความปลอดภัยโดนแฮ็กด้วยเรื่องพื้นฐานสุด ๆ อย่าง Security 101 สัปดาห์นี้ถึงคิวของ Accenture
แฮกเกอร์ที่ใช้ชื่อ “888” — บัญชีที่เคยมีผลงานไม่ค่อยน่าประทับใจกับบริษัทนี้มาก่อน — โผล่ขึ้นมาบนฟอรัมอาชญากรรมไซเบอร์ PwnForums อ้างว่าได้ขโมยซอร์สโค้ดของ Accenture ไปแล้ว “กว่า 35GB เล็กน้อย” พร้อมกับของอื่น ๆ ที่ไม่ควรหลุดออกจากตู้เซฟเด็ดขาด ทั้ง RSA key, SSH key, Azure personal access token และ Azure Storage access key เพื่อเป็นหลักฐาน พวกเขาโพสต์ภาพหน้าจอที่แสดงการดึงข้อมูลออกจากรีโพซิทอรี Azure DevOps ส่วนตัวที่เชื่อมโยงกับ URL การใช้งานจริงของ accenture.com
การตอบสนองของ Accenture เทียบได้กับการก้าวข้ามแอ่งน้ำโดยไม่ยอมรับว่าฝนกำลังตก คือ “รับทราบเหตุการณ์ที่เกิดขึ้นแบบแยกส่วนนี้” ต้นตอ “ได้รับการแก้ไขแล้ว” ไม่มีผลกระทบต่อการดำเนินงาน และไม่ยืนยันว่าจริง ๆ แล้วอะไรถูกขโมยไปบ้าง
รัฐบาลและห้องประชุมบอร์ดบริหารทุ่มเงินมหาศาลให้บริษัทที่ขายไอเดีย “เราจะตรวจสอบความปลอดภัยให้คุณ” กลายเป็นว่าการตรวจสอบนั้นไม่ได้เริ่มจากตัวเองเสมอไป
ส่วนที่ควรกวนใจใครก็ตามที่เคยดูแล pipeline CI/CD คือ ไม่มีอะไรในของที่ถูกอ้างว่าขโมยไปเป็นเรื่องพิเศษเลย ไม่ใช่ zero-day ไม่ใช่แผนโจมตี supply-chain ระดับรัฐชาติ ถ้าข้อกล่าวหาเป็นจริง นี่คือเรื่องเก่าแก่ที่สุดในวงการ DevOps นั่นคือ โทเคนและคีย์ที่อยู่ในรีโพนานเกินไป จนแค่ข้อมูลรับรองที่ถูกขโมยหรือไฟล์คอนฟิกที่หลุดออกไปก็เพียงพอจะเดินออกไปพร้อมของมีค่าที่สุดได้ ทั้งที่ธุรกิจหลักของ Accenture คือขายไอเดีย “เราจะช่วยไม่ให้คุณทำแบบนี้” ให้ลูกค้า ช่องว่างระหว่างโบรชัวร์กับรายงานการรั่วไหลนี่แหละคือจุดที่ตลกร้ายอยู่
สำหรับใครก็ตามที่ดูแลระบบโปรดักชัน — รวมถึงทีมคนเดียวที่ต่อ pipeline Python/ffmpeg เข้าด้วยกันโดยมี API key กระจัดกระจายอยู่ในไฟล์ CSV ที่ขับเคลื่อน batch job — บทเรียนจริง ๆ ไม่ใช่ “อย่าโดนแฮ็กสิ” แต่คือโทเคนการเข้าถึง SSH key และความลับของ API ต้องถูกเก็บไว้ในที่ที่ไม่ใช่ไฟล์คอนฟิกหรือข้อความ DM ใน Slack ต้องมีการหมุนเวียนและบันทึกการตรวจสอบ ไม่ใช่แค่ความรู้สึกว่าปลอดภัย
ทางแก้สำหรับความผิดพลาดรูปแบบนี้นั้นน่าเบื่อโดยตั้งใจ คือที่เก็บข้อมูลรับรองของทีมแบบเข้ารหัสและตรวจสอบได้ ทั้ง API key, SSH key, access token แทนที่ทุกคนจะแปะความลับลงในรีโพ สเปรดชีต หรือ Notion NordPass Business (และหมวดหมู่การจัดเก็บความลับที่กว้างกว่านั้น) ถูกสร้างมาเพื่อสิ่งนี้โดยเฉพาะ
Sources:แหล่งข้อมูล: Help Net Security, Bleeping Computer, Cybernews, GBHackers