Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
Ernst & Young Data Breach 🚨
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, stating that they obtained credentials for some of the company’s systems via a supply-chain attack. Ernst & Young disclosed the breach earlier this month, revealing that a third-party support ticket system used by its IT personnel was compromised, leading to the theft of support tickets that may contain client tax information.
EY detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents. According to the EY data breach notification, “EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients.” It further states that “Support tickets submitted through the platform may include documents containing client tax information” and that the stolen documents contained personal and financial information included in or used to prepare tax filings.
Today, the ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026. The threat actors claimed to BleepingComputer that EY credentials were obtained through a supply-chain attack and used to breach the company. These stolen credentials allegedly allowed them to breach Ernst & Young’s Jira, GitHub, and Azure environments. The threat actor would not identify the allegedly compromised third party or disclose what data was stolen. However, it claimed that the information EY acknowledged as compromised was exposed, along with more data. BleepingComputer has no way to verify the threat actor’s claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.
Ernst & Young previously stated that it secured its systems, removed the unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.