ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

July 29, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityaffairs.com

Threat Risk: High
Victim: Ernst & Young (EY)
Incident: Unauthorized access to a third-party support platform resulting in the theft of client tax documents.
Impact: Exposure of highly sensitive PII, including Social Security numbers and bank details for numerous clients.
Attacker: ShinyHunters
Analysis: The breach originated from a compromise within a third-party IT service management platform used for tax-related operations, bypassing EY’s core internal systems. ShinyHunters is now leveraging stolen high-value financial and personal identifiable information (PII) to pressure the firm into negotiations. This incident underscores the significant security risks inherent in third-party supply chain dependencies.
Recommendations: Audit and harden access controls for all third-party service management platforms.; Implement strict data minimization and encryption policies for sensitive documents uploaded to support tickets.; Enhance monitoring for anomalous data egress and unauthorized access within external vendor environments.
Source: Security Affairs

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *