Summary
- ShinyHunters has claimed responsibility for a data breach at Ernst & Young, one of the world’s largest professional services firms.
- The group alleges credentials to EY systems were obtained through a supply-chain attack rather than a direct intrusion.
- EY has disclosed the breach, though the full scope of compromised data is not confirmed in available source material.
- ShinyHunters has a documented history of large-scale data theft and extortion against major organisations.
- The incident underscores the credential exposure risk that flows from third-party and supplier relationships.
What has been claimed
The ShinyHunters extortion gang has publicly claimed responsibility for a data breach at Ernst & Young, stating it gained access to credentials for some of the firm’s systems through a supply-chain attack. The claim follows EY’s own disclosure of a breach, though the precise overlap between what EY has acknowledged and what ShinyHunters alleges has not been independently confirmed in available source material.
The supply-chain vector
ShinyHunters says the point of entry was not EY itself but a third party in its supply chain — a route that allowed the group to harvest credentials and move laterally into the firm’s environment. This is consistent with the group’s known operating pattern, which has involved exploiting trusted supplier relationships to reach otherwise well-defended targets. The specific third party involved has not been identified in the available source material.
Who is ShinyHunters
ShinyHunters is a well-documented threat actor with a history of large-scale data theft and extortion. The group has previously claimed breaches affecting hundreds of millions of records across multiple industries. Their method typically involves obtaining data and then leveraging the threat of public release to pressure victims, though they have also sold stolen data on criminal marketplaces. Their operational model is financially motivated rather than ideologically driven.
What remains unknown
The source material does not confirm the volume or nature of data obtained, which specific systems were accessed, whether any ransom demand has been made or is under negotiation, or the identity of the supplier through whom access was allegedly gained. EY has not, in the available reporting, publicly disputed or confirmed the specifics of ShinyHunters’ claims beyond acknowledging a breach occurred.
The broader pattern
Attacks on large professional services firms carry particular weight because of the breadth of client data and sensitive commercial information these organisations hold. A breach at an audit and advisory firm can have downstream implications for every client whose financial, operational, or strategic data passes through that firm’s systems. Whether or not ShinyHunters’ full claims are verified, the incident is a reminder that adversaries actively seek out the softest point in a chain of trust — and that suppliers and professional service partners are frequently that point.
Why it matters
For CISOs, this incident reinforces two compounding risks. First, your organisation’s security posture is only as strong as the weakest link in your third-party ecosystem — a well-resourced, well-defended firm like EY can still be reached through a supplier. Second, when a breach affects a major professional services provider, the exposure is not contained to that firm: client data, audit workpapers, advisory engagements, and financial information may all sit within the compromised environment. CISOs should assess whether EY or any similarly positioned firms have access to sensitive internal systems or data, review the contractual and technical controls governing that access, and confirm whether any notification obligations have been triggered.
What to do now
- Determine whether your organisation has active engagements with EY that involve data access or system integration, and request a formal breach notification assessment from your account relationship.
- Review third-party access credentials issued to EY or any of its affiliate tools and assess whether rotation or suspension is warranted pending further information.
- Use this incident as a prompt to audit credential access granted to all major professional services and advisory suppliers, particularly any with direct system or data access.
- Confirm your third-party risk management programme includes controls for how suppliers manage their own supply chains, not just their direct interface with your environment.
- Monitor for further disclosures from EY or credible reporting on the scope of compromised data before taking any premature public-facing action that could be based on unverified claims.
