ShinyHunters Claims Extortion of Ernst & Young Following ITSM Breach
- CVE ID
- N/A
- Affected Products / Orgs
- Ernst & Young (EY), EY client tax data
The ShinyHunters extortion gang has added accounting giant Ernst & Young to its public leak site, claiming responsibility for a recent Ernst & Young data breach that exposed sensitive client tax records. Unauthorized access to an internal support system occurred between March 28 and April 12, with EY detecting suspicious activity on April 23. While the firm initially disclosed the compromise of a third-party support platform earlier this month, the public listing by ShinyHunters significantly escalates the incident, with the threat actors setting a deadline of July 31, 2026, for the firm to pay an undisclosed ransom.
Timeline and Scope of the Breach
The intrusion centered on a third-party information technology service management (ITSM) platform utilized by EY IT personnel to assist teams executing client tax engagements. During the two-week window of exposure, the threat actor downloaded multiple documents attached to support tickets. EY confirmed that these stolen documents contained personal and financial information submitted or created for tax preparation and filings.
Upon detecting the activity on April 23, EY severed unauthorized access, secured the platform, and engaged federal law enforcement. The firm has begun notifying affected clients, offering 24 months of identity theft monitoring and restoration services through Experian. However, EY has withheld key operational specifics, including the exact identity of the third-party support vendor, the specific volume of compromised records, and the total number of impacted clients or individuals.
Threat Actor Claims and Supply-Chain Vectors
ShinyHunters claims the breach was executed through a supply-chain attack that yielded valid EY credentials. According to statements made by the group, these stolen credentials granted them initial access to the third-party ITSM system and subsequently allowed them to pivot into EY’s broader developer and infrastructure environments, specifically citing access to Jira, GitHub, and Azure instances.
While EY has confirmed the support ticket system compromise, it has not publicly corroborated the threat actor’s claims regarding downstream system access in Jira, GitHub, or Azure.
ShinyHunters is a well-established cybercrime group active since at least 2020, known for large-scale data theft and high-profile extortion campaigns targeting major cloud databases, corporate platforms, and consumer services. Rather than relying heavily on complex zero-day exploits, ShinyHunters traditionally prioritizes credential harvesting, cloud misconfigurations, third-party vendor compromises, and session hijacking. Their operational playbook routinely involves exfiltrating vast quantities of corporate data and listing victims on extortion sites to force financial settlements under threat of public leak or sale on cybercrime forums.
The Exposure Risk of ITSM Platforms
This incident highlights a major architectural risk facing enterprise organizations: third-party ITSM platforms operating as unmonitored “shadow repositories” of sensitive data. IT support ticketing systems frequently accumulate extensive, high-risk data assets. End users and support staff routinely attach diagnostic logs, database exports, configuration files, raw financial spreadsheets, and personal identifying information (PII) directly to support requests.
When an ITSM tenant or third-party service provider is breached, attackers gain access to structured, searchable repositories containing precisely the operational and personal data they seek. Furthermore, if IT support tickets contain hardcoded credentials, API tokens, or service account details uploaded during troubleshooting, threat actors can leverage that information to perform lateral movement into cloud tenants, source code repositories, and identity providers—matching the exact lateral trajectory ShinyHunters claims to have taken into EY’s Azure and GitHub environments.
Client Impact and Organizational Blast Radius
For a Big Four accounting firm like Ernst & Young, the blast radius of a tax data compromise extends beyond conventional enterprise PII exposure. Client tax filings contain deeply confidential corporate strategy documents, organizational structure details, revenue breakdowns, bank account information, and Social Security numbers.
The compromise of this data exposes affected corporate and individual tax clients to targeted spear-phishing, financial fraud, fraudulent tax filings, and regulatory fallout under state privacy mandates and IRS rules. Furthermore, if ShinyHunters’ claims of access to EY’s development repositories and cloud tenants prove accurate, the breach raises concerns regarding corporate software supply-chain integrity, service delivery codebases, and intellectual property protection.
Defensive Recommendations for ITSM Security
Organizations evaluating their own exposure to third-party SaaS and ticketing threats should implement strict controls around support platform data retention and access management:
- Automated Data Loss Prevention (DLP): Deploy DLP policies on ticketing portals and ITSM tools to automatically redact or block sensitive attachments, including PII, financial documents, API keys, passwords, and private SSH/cloud keys.
- Credential Hygiene in Support Channels: Enforce policy controls against pasting cleartext credentials or attaching raw configuration files to support tickets. Implement automated secret-scanning tools across support databases and integration pipelines.
- Strict Third-Party RBAC and MFA: Require phishing-resistant multi-factor authentication (MFA) across all third-party integration points, support portals, and administrative access routes. Restrict ticket access strictly based on the principle of least privilege, ensuring support agents and automated tools can only view tickets within their explicit scope.
Related content
Ernst & Young Discloses Data Breach Exposing Client Tax and Financial Information
Security NewsErnst & Young Reports Data Breach via Third-Party Platform
ResearchAnatomy of a Modern Supply Chain Attack — And Where Defenses Actually Break
Security NewsAdform Supply-Chain Attack Poisons Script to Swap Crypto Wallet Addresses
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call