Keys, licenses, and 12 million passwords: the week the plumbing leaked
The seller goes by “888,” and the listing is an inventory of exactly the things you never want inventoried: roughly 35GB of data allegedly taken from Accenture, including source code, RSA and SSH private keys, Azure personal access tokens, Azure Storage access keys, and configuration files. Every item on that list is the seller’s claim, posted to a crime forum, and none of it has been independently verified. What has been verified is narrower and stranger: Accenture told BleepingComputer’s Lawrence Abrams, who first reported the sale, that something did happen.
“We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery.”
“Isolated” is a word that will have to carry a lot of weight. Accenture’s business is building and operating systems inside other companies’ environments, which is why the specific items in the seller’s claimed haul matter more than the gigabyte count. RSA and SSH private keys and Azure tokens are not one company’s problem; they are, potentially, skeleton keys into whatever those credentials were provisioned to reach. The actor posted a screenshot that appeared to show an Azure DevOps repository being cloned from an Accenture-hosted domain. Accenture declined to say what was taken, how, or whether client data was involved. This is the firm’s third breach incident after LockBit in 2021 and a third-party compromise in 2024, per BleepingComputer.
On its own, a wire brief. The reason to slow down is that it was one of four disclosures between July 7 and July 9 that all leaked the same category of thing. Not marketing databases. Credentials: keys, tokens, licenses, passwords. The identity layer, the stuff that authenticates everything else.
Twelve million addresses and a vendor with no name
In Japan, KDDI spent the week putting hard numbers on a breach it first warned about in late June. The confirmed figures from KDDI’s disclosure, as reported by SecurityWeek’s Ionut Arghire and BleepingComputer’s Sergiu Gatlan: 12,233,087 email addresses and 7,616,173 passwords exposed from a shared email platform KDDI operates for itself and five other providers, including JCOM, NIFTY, and BIGLOBE. The Japan Times reported it as 12 million addresses and 7 million passwords; BleepingComputer’s June reporting on the initial warning put the ceiling at 14.22 million accounts once former customers and inactive mailboxes are counted. The numbers diverge because the disclosures do. Treat 12.2 million as confirmed, 14.2 million as the outer bound.
How the attackers got in is the uncomfortable part. KDDI says they exploited a previously unknown vulnerability in third-party software as early as May 16 and went undetected until June 17. Thirty-two days. The vendor is unnamed. There is no CVE. Per KDDI’s disclosure, as of the day the intrusion was found, “this vulnerability was not recognized by the software vendor,” which means every other operator of that software spent at least a month exposed to a hole that officially did not exist. A patch is still in development. KDDI has forced password resets and says it has no evidence of further suspicious activity; it also says some passwords were stored “hashed and/or encrypted,” without specifying the method or what portion sat in plaintext.
A shared platform, a nameless vendor, a bug with no number. If you wanted a diagram of why “change your password” is the least interesting sentence in a breach notice, this is it. The password is the one thing here that resets.
The number you can’t reset
Which brings us to Atlanta. AssuranceAmerica, a car insurer for higher-risk drivers, is notifying 6.99 million people that hackers took their names, contact details, auto policy and vehicle information, claims data, and driver’s license numbers, as first reported by TechCrunch’s Zack Whittaker from filings with the Maine and Indiana attorneys general. TechCrunch calls it the largest known breach of U.S. driver’s license numbers this year.
A password rotates in an afternoon. A driver’s license number follows you from renewal to renewal, and in most states you cannot get a new one by asking; you generally have to show the number has already been used for fraud. So the practical remedy on offer to those 6.99 million people is monitoring, which is another way of saying: watch for the harm, then file the paperwork after it arrives. The number stays live in the meantime, useful for synthetic identities, insurance fraud, and impersonating you to a DMV.
Note how the breach started, too. The company’s filing says attackers “targeted one of the Company’s employees,” after which it “disabled compromised credentials.” One person’s login on the way in; 6.99 million unrotatable numbers on the way out. The company’s CEO did not respond to TechCrunch’s questions, including whether a ransom was paid.
Meanwhile, on npm
The fourth incident is the smallest and the most explicit about intent. On July 7, Socket’s Joseph Edwards reported a cluster of 17 malicious packages, 13 on npm and four on PyPI, typosquatting SDKs for the payment platforms Paysafe, Skrill, and Neteller, with names like paysafe-checkout and plain skrill. The packages presented working facades of the real payment APIs while combing the environment for variables matching KEY, SECRET, TOKEN, PASS, AUTH, or API and shipping them to an ngrok endpoint. They fingerprinted the host and refused to run inside anything that looked like an analysis sandbox: fewer than two CPU cores, or a hostname containing strings like “vmware” or “cuckoo.”
Socket’s scanner flagged the cluster within six minutes of publication, which is genuinely good. But read the target list again. This campaign was not after cardholders. It was after developers’ credentials and CI/CD secrets, the tokens that publish software and touch production, at companies that move money.
Rotation asymmetry
Our read: this is not four coincidences, it’s one pricing decision. Attackers have worked out that the value of stolen data tracks how slowly it can be revoked. A password dies in seconds once the victim knows. An SSH key dies only after someone finds every server it was ever deployed to. An Azure token dies when someone remembers it exists. A driver’s license number, for most practical purposes, never dies at all. The week’s incidents sort neatly along that axis, and the sorting is not in defenders’ favor.
The disclosure clocks aren’t keeping up with any of it. KDDI’s attackers had 32 days before detection and the public got confirmed numbers about three weeks after that. Accenture confirmed its incident only after the seller advertised the merchandise. And AssuranceAmerica detected its intrusion on March 17. The notification letters go out July 10.
That’s 115 days. For 115 days, the only people who knew those 6.99 million license numbers were loose were the people who took them.
Priya covers the physical infrastructure of the digital world: power grids, data centres, undersea cables, and the climate math that ties them together. Based in New Delhi.
Leave a Reply