ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Tax Records
What Happened — ShinyHunters announced that it had accessed a third‑party service‑management platform used by Ernst & Young (EY) for tax‑related client support. Between 28 Mar 2026 and 12 Apr 2026 the actors downloaded documents attached to support tickets, exposing names, SSNs, bank and payment‑card details. The group is now threatening public release unless negotiations begin by 31 Jul 2026.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a third‑party service breach that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
- Continuous monitoring of third‑party access logs and periodic attestations provide the audit trail needed to demonstrate due‑diligence under the CC6 (Vendor Management) and CC7 (Risk Management) criteria.
- Mapping this breach to your SOC 2 readiness program highlights gaps in contract clauses, security‑as‑service assessments, and real‑time evidence collection—areas Verisq’s Vendor Risk capability can help close.
Who Is Affected – Professional‑services firms (audit, tax, consulting) and any organization that outsources client‑data handling to external ticketing or ITSM platforms.
Recommended Actions
- Immediately inventory all third‑party platforms that process client‑sensitive data and verify SOC 2‑type attestations.
- Enable continuous log‑streaming from those services into a central compliance repository for real‑time monitoring.
- Update vendor‑risk policies to require breach‑notification clauses and enforce periodic security‑assessment evidence.
Source: Security Affairs
Technical Notes – Attack vector: compromised credentials on a third‑party ITSM platform (no public CVE). Data types: personally identifiable information (PII) and financial data used for tax preparation.