This week was marked by several cybersecurity events, and since I am unable to cover them all in a single post, I will focus on the Accenture security breach reported this week. It was a week defined by fighting through a potential third‑party compromise (no, I don’t work at Accenture), diving into rabbit holes, and a few “Why the hell am I doing this job?” thoughts. This was my version of “another day in the IR paradise.”
Earlier this week, a security breach at Accenture was published in different media. I won’t go through the details of what happened or start sharing empty words about what Accenture should do better, as I’ve seen in other posts full of people speaking about an incident they have no context for, just to capture readers. Hell no — I respect incident responders too much for that. Instead, here’s the link: Accenture Data Breach — Hackers Allegedly Claim to Have Stolen 35 GB of Source Code
Now let me tell you, if you work in IR, from time to time you will have to get into these intels — not to try to figure out how an organization responded or how you could avoid the same thing happening to you. Because first, you have no idea about the root cause of a third‑party incident, and it is very possible that they are still trying to figure it out themselves while you are reading that report.
The day becomes shitty after reading one of these intels when somebody asks, “Do we do business with this company?” and somebody else says, “Yes.”
Getting into the Rabbit Hole
Yes, sometimes in IR you need to respond to incidents that didn’t even happen at your company, but at a third party. Accenture is a huge consulting and technology company with more than 700K employees around the globe, and many other companies do business with Accenture. So, if you’ve worked a few months in IR and your paranoia level is at an acceptable level, you start thinking about lateral movements, hypotheses, and how a Threat Actor can abuse any data extracted to attack your own organization.
Hunting Ghosts
With minimal to no context provided by one of these intels, our precautionary steps involved looking for any connection we had with the organization. That included any direct links connecting both environments and checking if any of their consultants still had access to ours. Sometimes it’s interesting to simply assume people’s accounts can be compromised and remediate them all. This can be called overreacting, but believe me, you’d rather do this than have regrets later.
Depending on the size of your company, this can be unfeasible, but my advice is: if you can do it, just do it. In my years of doing this job, I can tell you one of the biggest challenges is finding the right people at your company who can explain exactly what service a third party provides, including access to any system or data. That’s tough.
Another good piece of advice: if there is any connection, key, service account, etc., do a quick assessment of potential impact, communicate, and rotate them. If any of these keys were compromised and published on the dark web, you’ll have bad actors knocking at your door the next day.
Assume the Worst
With no context, sometimes you need to assume the worst‑case scenario. Let me tell you what I assumed in this case: if this company was compromised months ago and only found out now, they could have moved laterally into your company long ago. In this case, you will need to hunt through the activity of third‑party representatives, check their sign‑in patterns, locations, and the last time they rotated their passwords, etc.
Call Your PoCs
Any decent‑sized organization will have a point of contact. Sometimes it’s just the salespeople, other times it’s a dedicated account manager. It is always good to call them and ask if they have any idea whether the incident could have any potential impact on your company’s data. Most of the time they won’t know (yet) or won’t have permission to say. This is not about secrecy, it’s about not speaking on something they are still trying to figure out. But it’s still worth asking.
This week clearly highlighted how this role is not just about checking logs, but about assumptions, zero tolerance for risk, responding to potential risks that are not necessarily threats, and finding a way out of the rabbit hole. If one of this week’s days was barely stressful for me, I can’t imagine what it was like for my unknown colleagues at Accenture. I hope whoever was working on this incident managed to push through and start seeing the light at the end of the tunnel. It will get better, I promise.