ShinyHunters Claims Responsibility for EY Data Breach, Citing Supply Chain Attack
The notorious **ShinyHunters** extortion gang has publicly taken credit for a recent data breach affecting global professional services firm **Ernst & Young (EY)**. The group alleges a supply-chain attack granted them access to sensitive **EY** systems, including **Jira**, **GitHub**, and **Azure** environments, leading to the theft of client tax information.
# ShinyHunters Claims Responsibility for EY Data Breach, Citing Supply Chain Attack

The **ShinyHunters** extortion gang has formally claimed responsibility for a data breach impacting **Ernst & Young (EY)**, asserting they gained access to the firm's systems through a sophisticated supply-chain attack.
## Breach Details Emerge
**EY** initially disclosed the breach earlier this month, confirming that a third-party support ticket system used by its IT personnel had been compromised. This breach potentially exposed support tickets containing confidential client tax information.
**EY** detected unusual activity on April 23, determining that unauthorized access to the platform occurred between March 28 and April 12. During this period, multiple documents were reportedly downloaded.
According to **EY**'s data breach notification, the compromised platform is an information technology service management system used by **EY** IT personnel to support tax-related client work. The notification stated that support tickets submitted via this platform might include documents containing client tax information, as well as personal and financial details used in tax preparation.
Crucially, **EY** has not yet disclosed the name of the compromised support system, the specific types of information exposed beyond tax data, or the total number of affected individuals.
## ShinyHunters Enters the Fray
At the time of **EY**'s initial disclosure, no specific ransomware or data extortion group had claimed responsibility. However, **ShinyHunters** has now listed **Ernst & Young** on its data leak site, threatening to release the allegedly stolen data if the company does not engage with the group by July 31, 2026.

The threat actors informed BleepingComputer that **EY** credentials were acquired via a supply-chain attack. These credentials purportedly enabled them to breach **EY**'s **Jira**, **GitHub**, and **Azure** environments.
While **ShinyHunters** declined to name the specific third party allegedly compromised or detail all stolen data, they claim to possess the information **EY** has acknowledged, alongside additional undisclosed data.
## Unverified Claims and Ongoing Investigations
It is important to note that BleepingComputer has not independently verified **ShinyHunters**' claims, and **Ernst & Young** has not yet confirmed the group's involvement. BleepingComputer has reached out to **EY** for further comment regarding **ShinyHunters**' claims, potential extortion demands, the identity of the compromised support system, and the total number of affected individuals.
**Ernst & Young** previously stated that it has secured its systems, removed unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through **Experian**.