ShinyHunters Claims Theft of EY Client Tax Documents from Third‑Party Support Platform, Threatens Public Leak
What Happened — Ernst & Young confirmed that client tax documents were stolen from a third‑party support platform it uses. The hacker group ShinyHunters has claimed responsibility and is threatening to publish the data on July 31.
Why It Matters for Compliance & Audit Readiness
- This is a textbook example of a third‑party breach that SOC 2 vendor‑management controls (CC6.1) are designed to prevent and document.
- Continuous monitoring of vendor security posture provides audit‑ready evidence that due‑diligence was performed before the incident.
- A defensible audit trail showing how the organization responded (containment, notification, remediation) is essential for maintaining trust and meeting SOC 2 criteria.
Who Is Affected — Professional services firms (accounting, consulting) that rely on external support platforms for sensitive client data.
Recommended Actions
- Re‑evaluate the risk profile of the compromised support platform; request its latest SOC 2 Type 2 report and any security attestations.
- Implement continuous vendor‑risk monitoring to capture real‑time changes in security posture and feed that evidence into your audit repository.
- Update incident‑response playbooks to include third‑party breach scenarios and ensure timely client notification procedures.
Technical Notes — The breach originated from a third‑party support environment; no specific CVE was disclosed. Stolen data includes client tax filings (PII, financial information). Source: HackRead