Ernst & Young Data Breach Claimed by ShinyHunters
The notorious extortion gang ShinyHunters has claimed responsibility for the data breach disclosed earlier this month by the global consulting giant Ernst & Young. The group threatens to release the data by July 31st.
What Happened
The international audit and consulting giant Ernst & Young (EY) is now facing a public claim of responsibility for its recent data breach from a well-known actor in the cybercrime world: the ShinyHunters extortion gang. ShinyHunters added EY to its data leak site, claiming they were the ones who conducted the attack. The gang has threatened to publicly release the data it allegedly stole if the company does not contact them by July 31, 2026.
The chain of events began with the compromise of a third-party support ticket system used by EY's information technology (IT) personnel. In its data breach notification earlier this month, the company stated that it had detected suspicious activity in its systems on April 23. Subsequent investigations revealed that attackers had gained access to the platform between March 28 and April 12, during which they downloaded multiple documents. After detecting the breach, EY announced that it had secured its systems, removed the unauthorized access, and notified federal law enforcement agencies.
However, at the time of the initial disclosure, the identity of the attackers was unknown. No ransomware or data extortion group had claimed responsibility. The emergence of ShinyHunters on July 27 has changed the narrative, revealing that the potential motivation behind the breach is financial extortion. The group added EY to its list of victims on its dark web site, starting a countdown clock for the company. This tactic is commonly used by extortion groups to pressure victims into paying a ransom.
What Data Was Stolen
At the heart of the data breach is a support platform used by EY's IT personnel to assist teams performing tax-related work for clients. According to the company's official statement, support tickets submitted through this platform could contain documents with client tax information. This raises concerns that the leaked data could be highly sensitive.
The notification from EY stated that the stolen documents contained personal and financial information included in or used to prepare tax filings. Such documents typically include critical information like names, addresses, Social Security numbers, income details, and other sensitive financial data. However, EY has not provided a clear figure on the exact types of information leaked or the number of people affected by the breach.
The ShinyHunters gang, however, takes its claims a step further. Speaking to BleepingComputer, group members asserted that they possess more data than EY has acknowledged. They claim to have stolen not only tax information from support tickets but also data from the company's Jira, GitHub, and Azure environments. If true, this claim means the scope of the breach could be much larger than initially reported. These additional data sets, which could include Jira project management data, GitHub source codes, and Azure cloud infrastructure information, pose serious operational and reputational risks for the company. It is important to note, however, that these are claims made by ShinyHunters and have not yet been verified by Ernst & Young or independent sources.
How Did the Attack Happen
The most significant clue about how the attack was carried out comes from ShinyHunters' claim of a “supply-chain attack.” According to the group, instead of directly attacking Ernst & Young's systems, they targeted a less secure third-party vendor that provides services to the company. In this case, the target was an unnamed technology service management platform used by EY's IT staff.
ShinyHunters claims to have hacked this third-party platform to obtain administrative or user credentials for EY's systems. The attackers then used these stolen credentials to infiltrate EY's own internal networks. This method has become an increasingly popular tactic among cyberattackers in recent years. Since it is difficult to directly breach large, well-protected companies, attackers often target their smaller suppliers, which may have weaker cybersecurity measures. Once a supplier's system is compromised, it becomes much easier to access the main target through that system.
While EY has confirmed that the attack occurred via a third-party support ticket system, it has not publicly disclosed the name of this system. ShinyHunters' claim of accessing Jira, GitHub, and Azure environments may also have been made possible by the credentials obtained through this supply-chain attack. However, neither EY nor the attackers have shared further information about the precise technical details of the attack and the specific vulnerabilities exploited.
Who Is Affected
Those directly affected by this data breach are the clients of Ernst & Young who receive tax advisory services. Specifically, clients whose tax-related documents or information were uploaded to or processed through the compromised third-party support platform are at risk. The company has announced that it has begun notifying affected clients, but no official statement has been made regarding the total number of clients or individuals affected.
The fact that the leaked data includes personal and financial information related to tax filings exposes the affected individuals to serious risks such as identity theft, fraud, and targeted phishing attacks. The stolen information could be used by criminals to apply for fraudulent credit, take over bank accounts, or file false tax refund claims in the victims' names.
What You Can Do
Ernst & Young has announced that it is offering 24 months of identity monitoring and restoration services through Experian to clients affected by the breach. If you have received a notification from EY to this effect, the first thing you should do is activate this service immediately.
Here are some additional measures you can take:
- Check Your Credit Reports: Regularly review your credit reports to check for any suspicious accounts or loans opened in your name. If you notice any unusual activity, contact the relevant financial institution immediately.
- Fraud Alerts and Credit Freezes: You can contact credit bureaus to add a fraud alert to your accounts or, for a stronger measure, freeze your credit. A credit freeze prevents anyone from opening a new credit account in your name until you lift the freeze.
- Be Wary of Phishing Attacks: Attackers may use the stolen information to send you fake emails that appear to be from EY or an official institution. These emails may ask you for additional information or prompt you to click on a malicious link. Always be cautious of suspicious emails.
- Account Security: Change the passwords for your financial and email accounts to strong, unique ones. Enable two-factor authentication (2FA) wherever possible.
What the Company Is Saying
In its initial statement on the incident, Ernst & Young emphasized that it had brought the situation under control and taken the necessary steps. The company stated that a “third-party information technology service management platform” had been attacked, and that this platform helped IT personnel support teams doing tax-related work. It confirmed that the attackers accessed the platform and downloaded documents between March 28 and April 12.
EY also added that they had eliminated the unauthorized access, secured their systems, and informed federal law enforcement. Additionally, affected clients are being offered 24 months of identity monitoring services.
However, the company has not yet responded to BleepingComputer's questions regarding ShinyHunters' claims. EY has not confirmed whether ShinyHunters was behind the attack or if they have received a ransom demand from the group. Furthermore, important details such as the name of the compromised support system and the total number of people affected remain undisclosed.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.