The ShinyHunters ransomware group has claimed it infiltrated Ernst & Young’s internal network after obtaining credentials for certain company systems through an alleged supply chain attack.
added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026.
Last month, Ernst & Young informed its clients of a data breach after an unauthorised party accessed a third-party information technology service management platform used by the firm to support its tax operations.
On April 23, 2026, EY detected suspicious activity linked to unauthorised access of a platform used by its technology teams to support client tax service operations. In a filing with the California Department of Justice, the London-based firm said the attacker accessed the platform between March 28 and April 12, 2026, and downloaded client documents. EY noted that support requests stored on the system often include attachments, some of which may have contained clients’ personal and financial information related to their tax filings.
The firm is yet to disclose the number of affected individuals or the name of the third-party vendor involved.
The company said it partnered with an external cybersecurity firm to verify that the unauthorised access had been contained and that its systems were secure. EY added that it has found no signs of misuse or further disclosure of the exposed data and no indication that any specific individual was targeted in the attack. To support impacted clients, the company is providing 24 months of identity monitoring and restoration services through Experian IdentityWorks.
x.com/AlvieriD/status/2081754811838390437
The ShinyHunters extortion group has claimed responsibility for the cyber attack on Ernst & Young listing it as a victim on its data leak site. The group claimed that it had exfiltrated confidential data from EY and threatened to publish the entire database unless its ransom demands were satisfied.
The threat actors told BleepingComputer that they gained access to EY’s systems through a supply-chain attack involving stolen credentials, which were used to breach the company’s Jira, GitHub, and Azure environments. The attackers, however, did not disclose the compromised third party or the extent of the data allegedly stolen.
Click Here For The Original Source.
