Extortion Gang ShinyHunters Claims Responsibility for Ernst & Young Data Breach via Supply Chain Attack
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON — The cyber extortion group known as ShinyHunters claimed responsibility on July 27, 2026, for a significant data breach targeting the global professional services firm Ernst & Young. The gang stated that it gained unauthorized access to sensitive client and corporate information by exploiting a supply-chain vulnerability within a third-party support ticket system used by the accounting giant.
ShinyHunters announced the intrusion in a public statement released late on Sunday, asserting that compromised credentials from an external vendor allowed attackers to bypass Ernst & Young's primary security defenses. The group described the attack as a sophisticated operation designed to infiltrate the firm’s network through its supply chain rather than by directly attacking Ernst & Young's infrastructure. Once inside, the hackers allegedly exfiltrated terabytes of data before deploying ransomware demands.
The breach represents one of the most significant cybersecurity incidents involving major professional services firms in recent years. ShinyHunters indicated that the stolen dataset includes confidential financial records, internal communications, and proprietary client strategies. The group has threatened to release portions of this information publicly unless a substantial ransom is paid within 72 hours.
Ernst & Young confirmed it was aware of an active security incident involving its systems but declined to provide specific details regarding the scope of the data compromised or the identity of the attackers at press time. A company spokesperson stated that immediate containment measures were enacted and that forensic teams are working around the clock to assess the full impact on client operations.
The attack highlights growing concerns among cybersecurity experts about the risks posed by third-party vendors in corporate supply chains. By targeting a support ticket system managed by an external provider, ShinyHunters demonstrated how attackers can leverage weaker security postures at partner organizations to reach high-value targets like major accounting firms. This method bypasses traditional perimeter defenses that are often heavily fortified.
Law enforcement agencies and cybersecurity regulators have not yet commented on the incident or confirmed whether criminal investigations have been launched against the ShinyHunters group. The gang, which has previously targeted healthcare providers and financial institutions across Europe and North America, operates primarily through encrypted channels to coordinate attacks and negotiate ransoms.
As of Monday morning, it remains unclear how many clients were affected by the breach or whether any data had already been leaked prior to Ernst & Young's public acknowledgment. The firm has urged its clients to remain vigilant against potential phishing attempts that may follow in the wake of the disclosure. Questions persist regarding the specific third-party vendor involved and whether other organizations using similar support ticket systems face comparable risks.