Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

ShinyHunters Claims Theft of EY Client Tax Documents from Third‑Party Support Platform, Threatens Public Leak

Ernst & Young confirmed that a hacker group stole client tax documents from a third‑party support platform and is threatening to publish them. The incident highlights the need for robust vendor‑risk controls and continuous audit evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 hackread.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
hackread.com

ShinyHunters Claims Theft of EY Client Tax Documents from Third‑Party Support Platform, Threatens Public Leak

What Happened — Ernst & Young confirmed that client tax documents were stolen from a third‑party support platform it uses. The hacker group ShinyHunters has claimed responsibility and is threatening to publish the data on July 31.

Why It Matters for Compliance & Audit Readiness

  • This is a textbook example of a third‑party breach that SOC 2 vendor‑management controls (CC6.1) are designed to prevent and document.
  • Continuous monitoring of vendor security posture provides audit‑ready evidence that due‑diligence was performed before the incident.
  • A defensible audit trail showing how the organization responded (containment, notification, remediation) is essential for maintaining trust and meeting SOC 2 criteria.

Who Is Affected — Professional services firms (accounting, consulting) that rely on external support platforms for sensitive client data.

Recommended Actions

  • Re‑evaluate the risk profile of the compromised support platform; request its latest SOC 2 Type 2 report and any security attestations.
  • Implement continuous vendor‑risk monitoring to capture real‑time changes in security posture and feed that evidence into your audit repository.
  • Update incident‑response playbooks to include third‑party breach scenarios and ensure timely client notification procedures.

Technical Notes — The breach originated from a third‑party support environment; no specific CVE was disclosed. Stolen data includes client tax filings (PII, financial information). Source: HackRead

📰 Original Source
https://hackread.com/shinyhunters-ernst-young-ey-data-breach-threat-leak/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →