Accenture pentest gaffe: consultants flag HTTPS-protected passwords as plaintext finding

nptacek · x · 2026-09-19

Security researcher IceSolst recounts an on-site anecdote: Accenture consultants presenting a pentest readout flagged "passwords stored in plaintext" — a request the client observed was seen over HTTPS inside Burp Suite. The consultants' fallback justification ("if someone breaks HTTPS the password leaks, so it should be encrypted") became a widely shared joke about the technical depth of big-consultancy security work.

Original post →

More from Fun

Fun channel →