The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.
Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen.
EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents.
"EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients," reads the EY data breach notification.
"Support tickets submitted through the platform may include documents containing client tax information"
Th notification goes on to say that the stolen documents contained personal and financial information included in or used to prepare tax filings.
However, the company has not disclosed the name of the compromised support system, the specific types of information exposed, or how many people were affected.
At the time the breach was disclosed, no ransomware or data extortion group had claimed responsibility for the attack.
Today, the ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026.
Ernst & Young listed on the ShinyHunters data leak site
... continue reading