ShinyHunters Claims Ernst & Young Breach via Third-Party System

ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Table of Contents
    Add a header to begin generating the table of contents

    ShinyHunters added Ernst & Young to its data leak site on July 27, 2026, claiming a supply-chain attack that compromised a third-party support ticket system used by the firm. The extortion group claims the attack yielded client tax documents along with personal and financial data used in tax filings, and set a July 31 deadline for EY to make contact — threatening to release all stolen data if no response was received.

    ShinyHunters’ March-to-April Attack on EY’s Third-Party Ticket System

    According to the extortion posting, attackers accessed the compromised third-party platform between March 28 and April 12, 2026. EY detected unusual activity in the system on April 23, 2026, approximately eleven days after the claimed access window ended. EY secured the affected systems and removed unauthorized access following that detection.

    The breach was disclosed publicly in early July 2026 — roughly ten weeks after EY detected the intrusion. The extortion posting on July 27 followed the public disclosure and adheres to ShinyHunters’ pattern of listing victims publicly when extortion demands have not produced a settlement or when the group judges that public pressure will advance negotiations.

    EY confirmed unauthorized access to the third-party system and stated it had notified federal law enforcement and offered affected clients 24 months of identity monitoring through Experian. EY has not disclosed the number of individuals affected or identified the third-party vendor that operated the compromised support system.

    Claimed Lateral Movement Into EY’s Jira, GitHub, and Azure Environments

    ShinyHunters claims that credentials obtained from the third-party support ticket system provided access to EY’s internal Jira project management platform, GitHub repositories, and Azure cloud environments. If accurate, this describes a lateral movement from the initial third-party access point into EY’s core internal development and cloud infrastructure — substantially expanding the potential scope of the breach beyond the tax document exposure from the support ticket system.

    EY has not confirmed or denied the lateral movement claims. The firm’s public statements have addressed the third-party system access and the categories of client data involved, without speaking to the claim that ShinyHunters pivoted to Jira, GitHub, or Azure. The status of EY’s investigation into the full scope of the access remains ongoing.

    The July 31 Data Release Deadline and EY’s Incident Response

    ShinyHunters set July 31, 2026 as the deadline by which EY must contact the group or face public release of all stolen data. This compressed timeline, four days from the extortion posting, follows the group’s established pattern of using short public deadlines to pressure victim organizations during active negotiations.

    EY’s confirmed data categories from the breach include documents containing client tax information and personal and financial information used to prepare client tax filings. CEO Frank Calabrese’s statement that the matter is “subject to an ongoing investigation by the relevant authorities” and that disclosure constraints apply signals coordination with law enforcement or regulatory oversight that may limit what EY can say publicly about the investigation’s findings or scope.

    Client Tax Data Exposure at Scale Across Big Four Clientele

    Ernst & Young is one of the four largest professional services and accounting firms globally. Its client base includes large corporations, financial institutions, and high-net-worth individuals whose tax filings represent some of the most sensitive financial records they generate annually. The data EY confirmed was compromised — information used to prepare client tax filings — contains a concentration of personal and financial detail that can support identity fraud, financial account access, and targeted campaigns against the executives and corporations whose records were exposed.

    The supply-chain attack vector ShinyHunters describes — accessing a third-party support ticket system rather than EY’s primary infrastructure directly — illustrates the challenge professional services firms face in extending security controls across their vendor ecosystems. Third-party support platforms may operate under different security standards and monitoring coverage than the firm’s own systems, and credentials or data stored in support ticket systems can provide effective entry points to more sensitive environments if access is not properly segmented. The attack’s reported pivot from the ticket system to EY’s Jira and cloud environments, if confirmed, would represent exactly that pattern of credential-based lateral movement from a less-secured vendor platform to primary internal infrastructure.

    Related Posts