Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Ernst & Young data breach claimed by ShinyHunters extortion gang
    News

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    adminBy adminJuly 27, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    EY logo

    The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack.

    Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen.

    EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents.

    image

    “EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients,” reads the EY data breach notification.

    “Support tickets submitted through the platform may include documents containing client tax information”

    Th notification goes on to say that the stolen documents contained personal and financial information included in or used to prepare tax filings.

    However, the company has not disclosed the name of the compromised support system, the specific types of information exposed, or how many people were affected.

    At the time the breach was disclosed, no ransomware or data extortion group had claimed responsibility for the attack.

    Today, the ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026.

    Ernst & Young listed on the ShinyHunters data leak site
    Ernst & Young listed on the ShinyHunters data leak site
    Source: BleepingComputer

    The threat actors claimed to BleepingComputer that EY credentials were obtained through a supply-chain attack and used to breach the company. These stolen credentials allegedly allowed them to breach Ernst & Young’s Jira, GitHub, and Azure environments.

    The threat actor would not identify the allegedly compromised third party or disclose what data was stolen. However, it claimed that the information EY acknowledged as compromised was exposed, along with more data.

    BleepingComputer has no way to verify the threat actor’s claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.

    BleepingComputer contacted Ernst & Young again Monday morning to ask whether ShinyHunters was behind the attack and whether the company had received an extortion demand from the group.

    We also asked EY to identify the compromised support system and disclose how many people were affected by the breach.

    Ernst & Young previously said it secured its systems, removed the unauthorized access, and notified federal law enforcement.

    Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBeing a Luddite Is Fun Again
    admin
    • Website

    Related Posts

    News

    Being a Luddite Is Fun Again

    July 27, 2026
    News

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026
    News

    GitHub, PyPI add time-absed defenses against supply chain attacks

    July 26, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202638 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    July 27, 2026

    Being a Luddite Is Fun Again

    July 27, 2026

    Infosec News Nuggets — July 27, 2026 – AboutDFIR

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.