HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

ShinyHunters Claims Theft of EY Client Tax Documents from Third‑Party Support Platform, Threatens Public Leak

Ernst & Young confirmed that a hacker group stole client tax documents from a third‑party support platform and is threatening to publish them. The incident highlights the need for robust vendor‑risk controls and continuous audit evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 hackread.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
hackread.com

ShinyHunters Claims Theft of EY Client Tax Documents from Third‑Party Support Platform, Threatens Public Leak

What Happened — Ernst & Young confirmed that client tax documents were stolen from a third‑party support platform it uses. The hacker group ShinyHunters has claimed responsibility and is threatening to publish the data on July 31.

Why It Matters for Compliance & Audit Readiness

  • This is a textbook example of a third‑party breach that SOC 2 vendor‑management controls (CC6.1) are designed to prevent and document.
  • Continuous monitoring of vendor security posture provides audit‑ready evidence that due‑diligence was performed before the incident.
  • A defensible audit trail showing how the organization responded (containment, notification, remediation) is essential for maintaining trust and meeting SOC 2 criteria.

Who Is Affected — Professional services firms (accounting, consulting) that rely on external support platforms for sensitive client data.

Recommended Actions

  • Re‑evaluate the risk profile of the compromised support platform; request its latest SOC 2 Type 2 report and any security attestations.
  • Implement continuous vendor‑risk monitoring to capture real‑time changes in security posture and feed that evidence into your audit repository.
  • Update incident‑response playbooks to include third‑party breach scenarios and ensure timely client notification procedures.

Technical Notes — The breach originated from a third‑party support environment; no specific CVE was disclosed. Stolen data includes client tax filings (PII, financial information). Source: HackRead

📰 Original Source
https://hackread.com/shinyhunters-ernst-young-ey-data-breach-threat-leak/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →