HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

ShinyHunters Claims Supply‑Chain Credential Theft Exposed EY Client Tax Data

Ernst & Young disclosed a breach of a third‑party support ticket platform that may have exposed client tax information. The ShinyHunters extortion gang later claimed responsibility, alleging they obtained EY credentials via a supply‑chain attack and accessed internal systems. For compliance teams, this underscores the need for robust vendor‑risk controls and audit‑ready evidence of third‑party security.

LiveThreat™ Intelligence · 📅 July 27, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

ShinyHunters Claims Supply‑Chain Credential Theft Exposed EY Client Tax Data

What Happened — Ernst & Young disclosed that a third‑party IT support‑ticket platform used by its staff was compromised, resulting in the theft of support tickets that may contain client tax information. The ShinyHunters extortion gang later claimed responsibility, saying it obtained EY credentials through a supply‑chain attack and used them to access EY’s Jira, GitHub and Azure environments.

Why It Matters for Compliance & Audit Readiness

  • Highlights the importance of SOC 2 vendor‑management controls (CC6.1 Vendor Management, CC6.2 Third‑Party Risk Monitoring) to assess, monitor, and document third‑party security posture.
  • Demonstrates the need for continuous evidence collection on credential use and access‑log monitoring to satisfy audit requirements for incident response and data‑handling policies.
  • Shows how a Trust Center can provide audit‑ready proof of vendor‑risk assessments and remediation steps, reducing audit friction.

Who Is Affected — Professional‑services firms (accounting, consulting) and any organization that relies on third‑party ticketing or ITSM platforms for sensitive client work.

Recommended Actions

  • Review and strengthen your vendor‑risk management program to include continuous monitoring of third‑party SaaS credentials.
  • Map SOC 2 CC6.1 and CC6.2 controls to current evidence, capturing logs from all integrated ticketing and support tools.
  • Conduct a privileged‑access audit of internal systems (Jira, GitHub, Azure) and enforce MFA and least‑privilege principles.

Source: BleepingComputer

Technical Notes — The attackers reportedly leveraged a supply‑chain compromise of an unnamed ITSM platform to harvest credentials, then accessed EY’s internal environments. No ransomware was observed; the gang issued an extortion demand to prevent public release of the stolen documents. Source: same article

📰 Original Source
https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →