HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Tax Records

ShinyHunters accessed a third‑party service‑management platform used by EY, downloading client tax documents containing SSNs and bank details. The breach underscores the need for robust vendor‑risk controls and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Tax Records

What Happened — ShinyHunters announced that it had accessed a third‑party service‑management platform used by Ernst & Young (EY) for tax‑related client support. Between 28 Mar 2026 and 12 Apr 2026 the actors downloaded documents attached to support tickets, exposing names, SSNs, bank and payment‑card details. The group is now threatening public release unless negotiations begin by 31 Jul 2026.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of a third‑party service breach that SOC 2 vendor‑management controls are designed to detect, monitor, and evidence.
  • Continuous monitoring of third‑party access logs and periodic attestations provide the audit trail needed to demonstrate due‑diligence under the CC6 (Vendor Management) and CC7 (Risk Management) criteria.
  • Mapping this breach to your SOC 2 readiness program highlights gaps in contract clauses, security‑as‑service assessments, and real‑time evidence collection—areas Verisq’s Vendor Risk capability can help close.

Who Is Affected – Professional‑services firms (audit, tax, consulting) and any organization that outsources client‑data handling to external ticketing or ITSM platforms.

Recommended Actions

  • Immediately inventory all third‑party platforms that process client‑sensitive data and verify SOC 2‑type attestations.
  • Enable continuous log‑streaming from those services into a central compliance repository for real‑time monitoring.
  • Update vendor‑risk policies to require breach‑notification clauses and enforce periodic security‑assessment evidence.

Source: Security Affairs

Technical Notes – Attack vector: compromised credentials on a third‑party ITSM platform (no public CVE). Data types: personally identifiable information (PII) and financial data used for tax preparation.

📰 Original Source
https://securityaffairs.com/196239/data-breach/shinyhunters-claims-ernst-young-data-breach-threatens-to-leak-stolen-data.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →