ShinyHunters Claims Supply‑Chain Credential Theft Exposed EY Client Tax Data
What Happened — Ernst & Young disclosed that a third‑party IT support‑ticket platform used by its staff was compromised, resulting in the theft of support tickets that may contain client tax information. The ShinyHunters extortion gang later claimed responsibility, saying it obtained EY credentials through a supply‑chain attack and used them to access EY’s Jira, GitHub and Azure environments.
Why It Matters for Compliance & Audit Readiness —
- Highlights the importance of SOC 2 vendor‑management controls (CC6.1 Vendor Management, CC6.2 Third‑Party Risk Monitoring) to assess, monitor, and document third‑party security posture.
- Demonstrates the need for continuous evidence collection on credential use and access‑log monitoring to satisfy audit requirements for incident response and data‑handling policies.
- Shows how a Trust Center can provide audit‑ready proof of vendor‑risk assessments and remediation steps, reducing audit friction.
Who Is Affected — Professional‑services firms (accounting, consulting) and any organization that relies on third‑party ticketing or ITSM platforms for sensitive client work.
Recommended Actions —
- Review and strengthen your vendor‑risk management program to include continuous monitoring of third‑party SaaS credentials.
- Map SOC 2 CC6.1 and CC6.2 controls to current evidence, capturing logs from all integrated ticketing and support tools.
- Conduct a privileged‑access audit of internal systems (Jira, GitHub, Azure) and enforce MFA and least‑privilege principles.
Source: BleepingComputer
Technical Notes — The attackers reportedly leveraged a supply‑chain compromise of an unnamed ITSM platform to harvest credentials, then accessed EY’s internal environments. No ransomware was observed; the gang issued an extortion demand to prevent public release of the stolen documents. Source: same article