Particle.news
Download on the App Store

ShinyHunters Lists Ernst & Young on Darknet and Sets July 31 Deadline to Contact or Leak Data

The extortion group says it stole tax-related client documents via a supply‑chain credential compromise which, if published, could expose sensitive personal and financial data.

Overview

  • EY says it detected unusual activity on April 23 and found an attacker accessed a third-party support ticket platform between March 28 and April 12, downloading multiple client documents.
  • On July 27 ShinyHunters added EY to its darknet leak site, claimed responsibility, told reporters it used stolen credentials from a supply‑chain compromise to access EY systems, and demanded contact by July 31 or it will publish files.
  • Ernst & Young says it removed the unauthorized access, secured systems, notified federal law enforcement, and is offering affected clients 24 months of identity monitoring and restoration through Experian.
  • Key details remain undisclosed and unverified: EY has not named the compromised vendor, has not quantified how many clients or records were taken, and has not publicly confirmed ShinyHunters’ claims of access to Jira, GitHub or Azure.
  • Support‑ticket platforms often hold client tax filings and payment details, so published data could enable identity and tax fraud, prompt regulator and class‑action scrutiny, and increase focus on third‑party supply‑chain security.