discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.

By Lawrence Abrams·Jul 27·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Ernst & Young data breach claimed by ShinyHunters extortion gang
Image: bleepingcomputer.com

Ernst & Young data breach claimed by ShinyHunters extortion gang. The ShinyHunters gang says it obtained credentials for some of the company's systems via a supply-chain attack. The breach occurred between March 28 and April 12, and the attacker downloaded multiple documents. The stolen documents contained personal and financial information included in or used to prepare tax filings.

Why it matters

The breach highlights the importance of securing third-party systems and the potential risks of supply-chain attacks. It also raises concerns about the potential for sensitive information to be compromised.

Imagine you have a big box of important papers, and someone breaks into your house and steals the box. That's basically what happened to Ernst & Young, a big company that helps people with their taxes. The bad guys, called ShinyHunters, broke into Ernst & Young's computer system and stole some papers that had important information on them. Now, the bad guys are threatening to release the papers unless Ernst & Young pays them money.

Analysis

A $60B Vote of Confidence

The recent data breach at Ernst & Young (EY) has sent shockwaves through the business world, with the ShinyHunters extortion gang claiming responsibility for the attack. The breach, which occurred between March 28 and April 12, has raised concerns about the potential for sensitive information to be compromised. According to EY, the attacker accessed the company's third-party information technology service management platform, which is used to provide support to EY teams performing tax-related work for clients. The stolen documents contained personal and financial information included in or used to prepare tax filings.

The breach highlights the importance of securing third-party systems and the potential risks of supply-chain attacks. EY has not disclosed the name of the compromised support system, the specific types of information exposed, or how many people were affected. However, the company has secured its systems, removed the unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.

Why Cursor?

The ShinyHunters gang's claim of responsibility for the breach raises questions about the motivations behind the attack. The gang has a history of targeting companies and releasing stolen data, but the exact reasons for this attack are unclear. It is possible that the gang was motivated by financial gain, or that it was seeking to disrupt EY's operations. Regardless of the motivations, the breach highlights the importance of securing third-party systems and the potential risks of supply-chain attacks.

The Road Ahead

The breach at EY is a reminder that companies must be vigilant in securing their systems and protecting sensitive information. The use of third-party systems can create vulnerabilities that attackers can exploit, and companies must take steps to mitigate these risks. This includes implementing robust security measures, conducting regular risk assessments, and providing training to employees on cybersecurity best practices. By taking these steps, companies can reduce the risk of a breach and protect sensitive information.

Key points

  • The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach.
  • The breach occurred between March 28 and April 12, and the attacker downloaded multiple documents.
  • The stolen documents contained personal and financial information included in or used to prepare tax filings.
  • Ernst & Young has secured its systems, removed the unauthorized access, and notified federal law enforcement.
  • Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
The Upside

Ernst & Young has taken steps to secure its systems and protect sensitive information. The company has removed the unauthorized access and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian. This shows that Ernst & Young is taking the breach seriously and is working to mitigate the damage.

The Downside

The breach highlights the potential risks of supply-chain attacks and the importance of securing third-party systems. If Ernst & Young had not taken steps to secure its systems, the breach could have been much worse. The stolen documents contained personal and financial information included in or used to prepare tax filings, which could have been used for identity theft or other malicious purposes.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsdata_breachsecurityernst_and_youngshinyhuntersextortion

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Jul 27, 2026

Source

bleepingcomputer.com

Share

Topics

data_breachsecurityernst_and_youngshinyhuntersextortion

Related

More from this desk

Jul 27·bleepingcomputer.com

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack

Coca-Cola has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. The company says it is still working to restore some of the impacted systems and operations, but most of the production in the U.S. has been…

Jul 27·thehackernews.com

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A public exploit has been released for a patched vBulletin pre-auth code execution flaw. The exploit requires no account, administrative access, or interaction from another user and can execute code on an unpatched forum server.

Jul 27·thehackernews.com

Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach of Huggin…

Jul 27·bleepingcomputer.com

Shadow AI Agents Are Multiplying. Here's How to Find and Secure Them.

Shadow AI agents are multiplying across various platforms, posing a significant risk to organizations. Nudge Security provides a solution to discover and secure these agents, ensuring visibility and control while enabling the workforce to experiment and automate.