ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

ShinyHunters claims EY breach after obtaining internal system credentials

The ShinyHunters ransomware group has claimed it infiltrated Ernst & Young’s internal network after obtaining credentials for certain company systems through an alleged supply chain attack.

 

added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026.

 

Last month, Ernst & Young informed its clients of a data breach after an unauthorised party accessed a third-party information technology service management platform used by the firm to support its tax operations.

 

On April 23, 2026, EY detected suspicious activity linked to unauthorised access of a platform used by its technology teams to support client tax service operations. In a filing with the California Department of Justice, the London-based firm said the attacker accessed the platform between March 28 and April 12, 2026, and downloaded client documents. EY noted that support requests stored on the system often include attachments, some of which may have contained clients’ personal and financial information related to their tax filings.

 

The firm is yet to disclose the number of affected individuals or the name of the third-party vendor involved.

 

The company said it partnered with an external cybersecurity firm to verify that the unauthorised access had been contained and that its systems were secure. EY added that it has found no signs of misuse or further disclosure of the exposed data and no indication that any specific individual was targeted in the attack. To support impacted clients, the company is providing 24 months of identity monitoring and restoration services through Experian IdentityWorks.

 

 

The ShinyHunters extortion group has claimed responsibility for the cyber attack on Ernst & Young listing it as a victim on its data leak site. The group claimed that it had exfiltrated confidential data from EY and threatened to publish the entire database unless its ransom demands were satisfied.

 

The threat actors told BleepingComputer that they gained access to EY’s systems through a supply-chain attack involving stolen credentials, which were used to breach the company’s Jira, GitHub, and Azure environments. The attackers, however, did not disclose the compromised third party or the extent of the data allegedly stolen.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543