Hackers claim breach of Ernst & Young data in ShinyHunters extortion

▼ Summary
– The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials through a supply-chain attack.
– Ernst & Young disclosed the breach earlier, reporting that a third-party support ticket system was compromised, potentially exposing client tax information.
– The attacker accessed the platform from March 28 to April 12, downloading documents containing personal and financial information from tax filings.
– ShinyHunters threatened to release the stolen data unless Ernst & Young contacts them by July 31, 2026, and claimed to have breached Jira, GitHub, and Azure environments.
– Ernst & Young has not confirmed ShinyHunters’ involvement, secured its systems, removed unauthorized access, and notified federal law enforcement, offering affected clients 24 months of identity monitoring.
The ShinyHunters extortion group has publicly taken credit for the Ernst & Young data breach that was disclosed earlier this month, alleging that the attack originated through a supply-chain compromise that yielded access credentials to the firm’s internal systems.
Ernst & Young first revealed the security incident in early July, explaining that a third-party support ticket system used by its IT staff had been infiltrated. That platform, which helps manage requests related to client tax work, held documents that could include sensitive client tax information. The firm detected suspicious activity on April 23 and determined that an attacker had accessed the system between March 28 and April 12, downloading multiple files during that window.
According to EY’s official breach notification, the stolen documents contained personal and financial data used in or prepared for tax filings. However, the company has not named the compromised vendor, specified exactly what types of information were exposed, or disclosed how many individuals were impacted.
When the breach was first made public, no ransomware or extortion group had claimed responsibility. That changed over the weekend when ShinyHunters added Ernst & Young to its data leak website, threatening to release the allegedly stolen data unless the company contacts the group by July 31, 2026.
Speaking with BleepingComputer, the threat actors asserted that they obtained EY credentials through a supply-chain attack and used them to breach the company’s Jira, GitHub, and Azure environments. They declined to identify the compromised third party or specify what data was taken, but claimed that the information EY acknowledged was stolen is only part of a larger trove.
BleepingComputer has not independently verified these claims, and Ernst & Young has not confirmed that ShinyHunters is behind the incident. BleepingComputer reached out to EY again on Monday to ask whether the company received an extortion demand from the group, and also requested details about the compromised support system and the total number of affected individuals.
In its earlier disclosure, Ernst & Young stated that it had secured its systems, removed the unauthorized access, and notified federal law enforcement. The firm is offering affected clients 24 months of identity monitoring and restoration services through Experian.
(Source: BleepingComputer)




