Ernst & Young data breach claimed by ShinyHunters extortion gang

Ernst & Young’s Data Breach Exposes Client Tax Information, Raises Concerns Over Supply-Chain Attacks

A major cybersecurity incident has unfolded at Ernst & Young (EY), one of the world’s largest professional services firms. The company disclosed a data breach earlier this month, where an attacker compromised its third-party support ticket system, potentially exposing sensitive client tax information. Now, the ShinyHunters extortion gang has claimed responsibility for the attack, threatening to release allegedly stolen data unless EY contacts them by July 31.

According to EY’s notification, the breach occurred between March 28 and April 12, when an attacker downloaded multiple documents from the compromised support ticket system. The platform in question is used by EY’s IT personnel to provide support for tax-related work for clients. Support tickets may contain client tax information, which could include personal and financial data used to prepare tax filings.

The ShinyHunters gang claims to have obtained EY credentials through a supply-chain attack, allowing them to breach the company’s Jira, GitHub, and Azure environments. While BleepingComputer has no way to independently verify these claims, the group’s track record suggests that their threat is credible. ShinyHunters has been linked to several high-profile data breaches in recent months, including a PeopleSoft breach where public data was stolen.

The lack of transparency from EY regarding the compromised support system and the specific types of information exposed raises concerns about how the company handles sensitive client data. The fact that no ransomware or data extortion group had claimed responsibility for the attack at the time of its disclosure adds to the mystery surrounding this incident.

As more details emerge, it’s becoming increasingly clear that supply-chain attacks are a growing concern in the cybersecurity landscape. These types of attacks involve compromising third-party vendors or services to gain access to sensitive systems and data. By using stolen credentials, attackers can move undetected through an organization’s environment, causing significant damage before being detected.

In response to the breach, EY has secured its systems, removed unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.

This incident serves as a reminder that even top-tier companies like Ernst & Young can be vulnerable to sophisticated attacks. It’s essential for organizations to take proactive measures to protect themselves against supply-chain attacks, including regularly testing their security controls and implementing robust incident response plans.

For individuals and businesses alike, this breach highlights the importance of being vigilant about cybersecurity. With the rise of supply-chain attacks, it’s crucial to stay informed about potential threats and take steps to protect sensitive data. By staying proactive and educated on cybersecurity best practices, we can reduce our vulnerability to such incidents and better safeguard ourselves against the ever-evolving threat landscape.


Source: Bleeping Computer — 2026-07-27