2 Remove Virus

ShinyHunters Claims Responsibility for Ernst & Young Data Breach

The ShinyHunters extortion group has claimed responsibility for a data breach recently disclosed by professional services firm Ernst & Young (EY), alleging that it gained access to the company’s systems through a supply-chain compromise. EY has not confirmed that ShinyHunters was behind the incident, and the group’s claims have not been independently verified.

 

 

Earlier this month, EY disclosed that a third-party IT service management platform used by its support teams had been compromised. According to the company, the platform is used by IT personnel assisting teams that perform tax-related work for clients.

EY said it detected suspicious activity on April 23 and determined that an unauthorized party had access to the support platform between March 28 and April 12. During that period, multiple documents were downloaded from the system.

The company said support tickets submitted through the platform may contain documents related to client tax work. According to its notification, some of the downloaded files included personal and financial information used in or associated with tax return preparation.

EY has not identified the third-party support platform involved in the breach. The company also has not disclosed how many individuals were affected or provided a detailed breakdown of the exposed information.

When the incident was first announced, no ransomware or extortion operation had publicly claimed responsibility. That changed after ShinyHunters added EY to its leak site and threatened to publish what it described as stolen company data if contact was not established before July 31, 2026.

The group also claimed it obtained EY credentials through a supply-chain attack before using them to access the company’s Jira, GitHub and Azure environments. Those allegations originate solely from the threat actor and have not been confirmed by EY or independently verified.

ShinyHunters did not identify the third party it claims was compromised or provide evidence supporting its account of the intrusion. The group further alleged that it obtained additional information beyond the documents EY acknowledged had been accessed, but it did not disclose the nature of the purported data.

Following discovery of the incident, EY said it secured the affected environment, removed the unauthorized access and notified federal law enforcement. The company has not publicly commented on whether it has received an extortion demand from ShinyHunters or whether it believes the group was responsible for the attack.

As part of its response, EY is offering affected clients 24 months of identity monitoring and identity restoration services through Experian. The company has not announced further details about the investigation, while the claims made by ShinyHunters remain unverified.