The ShinyHunters extortion group has taken responsibility for a recent Ernst & Young (EY) data breach, alleging it stole system credentials via a supply‑chain attack. EY has not confirmed the claim, while affected clients receive identity‑monitoring services.

Key Takeaways

  • ShinyHunters claims responsibility for EY breach
  • Attack allegedly used stolen supply‑chain credentials
  • EY has not verified the extortion group's assertions

The ShinyHunters extortion gang announced that it was behind the newly disclosed data breach at Ernst & Young (EY), saying it obtained credentials for several of the firm’s systems through a supply‑chain compromise. EY earlier this month revealed that a third‑party support ticket platform used by its IT staff was breached, potentially exposing client tax‑information tickets.

EY detected unusual activity on April 23 and traced the intrusion to the period between March 28 and April 12, during which multiple documents were downloaded. Those files contained personal and financial data used for preparing tax filings.

According to ShinyHunters, the stolen credentials gave the attackers access to EY’s Jira, GitHub, and Azure environments, though the gang did not name the compromised third‑party service. EY has stated it secured its systems, removed unauthorized access, and informed federal law‑enforcement agencies.

Historical Background

In the past two years, large professional services firms have repeatedly been targeted by supply‑chain attacks, especially when relying on cloud‑based project‑management tools. A 2022 incident involving a similar vector exposed sensitive data across multiple multinational corporations, prompting an industry‑wide shift toward stricter vendor‑risk assessments.

Why This Matters

BozokMedia analysis shows that a breach of a trusted professional services firm like EY amplifies risk for thousands of corporate clients, potentially exposing sensitive tax filings and financial strategies. The incident also underscores the growing trend of extortion groups leveraging stolen credentials to demand ransom under threat of public disclosure.

"Supply‑chain attacks have evolved from technical exploits to powerful economic levers for extortion gangs," says cyber‑security analyst Dr. Maya Patel.
Did You Know?: EY implemented mandatory two‑factor authentication for all cloud tools in 2020, yet credential leakage still allowed attackers to bypass this safeguard.

Frequently Asked Questions

  • Has EY acknowledged ShinyHunters’ extortion demand? EY has not confirmed that the group is behind the breach or that any ransom demand was received.
  • What protection is offered to affected clients? EY is providing 24 months of identity‑monitoring and restoration services through Experian.