Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young, saying it gained access to company systems through a supply-chain attack that yielded valid credentials. EY has disclosed the breach, though the full scope of compromised data has not been confirmed.
Why this matters: Ernst & Young works with some of the largest companies and governments in the world. That means a breach there is not just EY's problem. Client financials, audit records, tax data, and sensitive business information could all be in the mix. Supply-chain attacks are particularly hard to defend against because the entry point is someone else's weakness, not yours. ShinyHunters has a long track record of turning stolen data into leverage. Anyone whose information passed through EY has a real reason to want specifics, and EY has a real obligation to give them.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.