Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.
Intelligence analysis by Llama

Ernst & Young data breach claimed by ShinyHunters extortion gang. The ShinyHunters gang says it obtained credentials for some of the company's systems via a supply-chain attack. The breach occurred between March 28 and April 12, and the attacker downloaded multiple documents. The stolen documents contained personal and financial information included in or used to prepare tax filings.
Imagine you have a big box of important papers, and someone breaks into your house and steals the box. That's basically what happened to Ernst & Young, a big company that helps people with their taxes. The bad guys, called ShinyHunters, broke into Ernst & Young's computer system and stole some papers that had important information on them. Now, the bad guys are threatening to release the papers unless Ernst & Young pays them money.
Analysis
A $60B Vote of Confidence
The recent data breach at Ernst & Young (EY) has sent shockwaves through the business world, with the ShinyHunters extortion gang claiming responsibility for the attack. The breach, which occurred between March 28 and April 12, has raised concerns about the potential for sensitive information to be compromised. According to EY, the attacker accessed the company's third-party information technology service management platform, which is used to provide support to EY teams performing tax-related work for clients. The stolen documents contained personal and financial information included in or used to prepare tax filings.
The breach highlights the importance of securing third-party systems and the potential risks of supply-chain attacks. EY has not disclosed the name of the compromised support system, the specific types of information exposed, or how many people were affected. However, the company has secured its systems, removed the unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
Why Cursor?
The ShinyHunters gang's claim of responsibility for the breach raises questions about the motivations behind the attack. The gang has a history of targeting companies and releasing stolen data, but the exact reasons for this attack are unclear. It is possible that the gang was motivated by financial gain, or that it was seeking to disrupt EY's operations. Regardless of the motivations, the breach highlights the importance of securing third-party systems and the potential risks of supply-chain attacks.
The Road Ahead
The breach at EY is a reminder that companies must be vigilant in securing their systems and protecting sensitive information. The use of third-party systems can create vulnerabilities that attackers can exploit, and companies must take steps to mitigate these risks. This includes implementing robust security measures, conducting regular risk assessments, and providing training to employees on cybersecurity best practices. By taking these steps, companies can reduce the risk of a breach and protect sensitive information.
Key points
- The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach.
- The breach occurred between March 28 and April 12, and the attacker downloaded multiple documents.
- The stolen documents contained personal and financial information included in or used to prepare tax filings.
- Ernst & Young has secured its systems, removed the unauthorized access, and notified federal law enforcement.
- Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
Ernst & Young has taken steps to secure its systems and protect sensitive information. The company has removed the unauthorized access and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian. This shows that Ernst & Young is taking the breach seriously and is working to mitigate the damage.
The breach highlights the potential risks of supply-chain attacks and the importance of securing third-party systems. If Ernst & Young had not taken steps to secure its systems, the breach could have been much worse. The stolen documents contained personal and financial information included in or used to prepare tax filings, which could have been used for identity theft or other malicious purposes.



