Breach report · Technology
Accenture Ransomware Attack
LockBit ransomware attackers claimed 6TB of Accenture's data and demanded a $50 million ransom; Accenture restored from backup and refused to pay.
Exploit: Ransomware Company: Accenture Industry: Financial, Consulting Firm Sources: threatpost.com
Multiple databases belonging to global consulting giant Accenture have been listed for sale on the LockBit ransomware gang’s dark web site. LockBit claims to have 6 terabytes of Accenture’s data, for which it is requesting a ransom of $50 million for its return. Media outlets have shown conflicting reports, with some speculating this may have been the result of an inside job.
Accenture has a client book of hundreds of extremely high-profile global businesses, many of which appear on the Fortune Global 100 and Fortune Global 500 lists. For this reason, eyes have been on how this incident plays out and what is included in the compromised data.
Company officials offered reassurance, stating, “Through our security controls and protocols, we identified irregular activity in one of our environments. We immediately contained the matter and isolated the affected servers.” They went on to say, “We fully restored our affected systems from backup, and there was no impact on Accenture’s operations, or on our clients’ systems.”
Accenture continued to seemingly downplay the effects of the incident in an internal memo reported on by CyberScoop. The memo reads, “While the perpetrators were able to acquire certain documents that reference a small number of clients and certain work materials we had prepared for clients, none of the information is of a highly sensitive nature.”
For now, Accenture appears confident in its stance and has not paid the requested ransom in the first window, with the hopes that it, and its clients, are secure from any further costs and damages.