LockBit 2.0 published files it said it had stolen from Accenture on August 11, 2021. Accenture said it contained the incident, isolated affected servers, restored affected systems from backup, and saw no impact to its operations or client systems. In an October 2021 filing, the company later confirmed that a third party had extracted proprietary information and made some of it public. The attackers’ claims about the amount stolen and the ransom demand were not confirmed by Accenture.
What happened in the Accenture ransomware incident?
On August 11, 2021, LockBit 2.0 listed Accenture on its leak site and threatened to publish files it claimed to have taken from the company. The Record reported that the countdown ended and files appeared on the site that day. Accenture’s spokesperson said the company had identified irregular activity in one environment, contained it, isolated affected servers, and restored affected systems from backup. The spokesperson said there was no impact to Accenture’s operations or clients’ systems. The Record’s contemporaneous account includes the company’s statement and description of the leak.
What did Accenture confirm later?
In its fiscal 2021 Form 10-K, Accenture disclosed that during the fourth quarter of that fiscal year it identified irregular activity that included a third party extracting proprietary information. The company said some of that information was made public by the third party. SecurityWeek and BleepingComputer reported this filing disclosure; it confirms extraction and public release, but not the full amount or contents of the data. SecurityWeek’s report reproduces the filing language.
What was claimed, reported, and confirmed?
| Point | What the sources establish |
|---|---|
| Data volume | LockBit claimed it had stolen over 6 terabytes; Accenture’s filing did not verify this figure. SecurityWeek |
| Ransom demand | LockBit reportedly demanded $50 million; this was an attacker claim, not a figure confirmed by Accenture. SecurityWeek |
| Files published | SecurityWeek reported that more than 2,000 files were published. This is the outlet’s reported count, not an Accenture-confirmed total. SecurityWeek |
| Data extraction and publication | Accenture’s fiscal 2021 filing, as reported by SecurityWeek, confirmed that a third party extracted proprietary information and made some of it public. |
| Operational impact | Accenture said at the time that its operations and clients’ systems were not affected. The Record |
What kind of files were involved?
Contemporaneous reporting described visible leaked material as brochures, employee training courses, and marketing material. CyberScoop later reported that an internal memo described documents referencing a small number of clients and work materials prepared for clients. Accenture denied a later LockBit claim that customer credentials were stolen, citing its forensic review. That denial does not establish that no client-related material was involved: the accounts describe some documents that referenced clients, but do not establish the complete inventory or sensitivity of all extracted data. CyberScoop’s report covers the internal memo and the company’s response.
#1 Best Overall
How did LockBit get access?
The access path was not established in the cited contemporaneous reporting. LockBit made an insider-access claim, and outside speculation circulated, but The Record said the speculation lacked evidence. The available accounts therefore do not support attributing the intrusion to a particular vulnerability, credential compromise, insider, or other entry method. The Record reported that the question remained unanswered.
Timeline of the 2021 incident
- July 30, 2021: Accenture’s detection date was later reported by CyberScoop based on the company’s SEC filing account. CyberScoop
- August 11, 2021: LockBit’s leak-site threat became public; Accenture described containment and restoration, and The Record reported that files appeared after the countdown ended. The Record
- October 2021: Accenture’s fiscal 2021 filing acknowledged extraction of proprietary information and public release of some of it, as reported by SecurityWeek. SecurityWeek
Is this the same as the 2026 Accenture report?
No. TechRadar Pro reported on July 9, 2026, that Accenture acknowledged a separate “isolated matter” and said it had remediated its source, with no impact on operations or service delivery. Claims by that actor about an archive, its contents, and its volume were not independently verified in that report. That later event is separate and does not provide evidence about the 2021 LockBit incident. TechRadar Pro’s July 2026 report describes the later matter.
Quick Recap
Best Value
Rank #4
Rank #3
Rank #2
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

