2021 Accenture — LockBit ransomware incident with confirmed proprietary data theft
Data compromised
Proprietary corporate information; some documents reportedly referencing a small number of clients and work materials
Technical writeup
In August 2021, Accenture confirmed a LockBit ransomware-related security incident after detecting irregular activity, isolating affected servers, and restoring systems from backups. Later public reporting and Accenture disclosures indicated third parties extracted proprietary information from one environment and some of that data was published by the threat actor. Reporting also referenced actor claims of a larger data haul and ransom demand, while Accenture said there was no operational impact and no direct impact on client systems.
Root cause
Ransomware intrusion (LockBit) with unauthorized access and data exfiltration from a corporate environment
References
- https://www.reuters.com/technology/accenture-restores-affected-systems-after-reported-ransomware-attack-2021-08-11/
- https://www.bleepingcomputer.com/news/security/accenture-confirms-hack-after-lockbit-ransomware-data-leak-threats/
- https://www.bleepingcomputer.com/news/security/accenture-confirms-data-breach-after-august-ransomware-attack/
- https://cyberscoop.com/accenture-ransomware-lockbit/