Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

Ernst & Young data breach claimed by ShinyHunters extortion gang

ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Ernst & Young (EY) is a major global professional services firm; a breach affecting their systems could impact numerous downstream clients and their supply chains.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • Ernst & YoungProfessional services firm; credentials for company systems compromised

Ernst & Young (EY), a major global professional services and consulting firm, has been targeted in a data breach claimed by the ShinyHunters extortion gang. According to the threat actor's claim, credentials for some of EY's systems were obtained through a supply-chain attack vector.\n\nThe breach was recently disclosed, and ShinyHunters has publicly claimed responsibility, indicating active extortion activity. As a major professional services provider serving enterprises across multiple industries, a compromise of EY's systems could have cascading effects on their clients and downstream supply chains.\n\nThe specific technical details of the supply-chain attack vector used to obtain the credentials have not been fully disclosed in the available information.

Remediation

  • Conduct a comprehensive audit of Ernst & Young's systems and access controls to identify all compromised credentials
  • Reset credentials for all affected systems and implement multi-factor authentication
  • Notify all clients and downstream partners who may be affected by the breach
  • Investigate the supply-chain attack vector used to obtain initial access
  • Review and strengthen vendor and third-party access controls
  • Monitor for unauthorized access attempts using the compromised credentials

Sources

  1. Ernst & Young data breach claimed by ShinyHunters extortion gang · BleepingComputer

Cite this entry

"Ernst & Young data breach claimed by ShinyHunters extortion gang." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 27, 2026; last updated July 27, 2026. https://supplychainattack.org/incident/ernst-young-data-breach-claimed-by-shinyhunters-extortion-gang-kokojd

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedhigh

    Polymarket customers lose $3 million in supply-chain attack

    Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.

    OtherThird-party vendor breach
  2. containedhigh

    LastPass confirms data breach in Klue supply chain attack

    LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.

    OtherThird-party vendor breach
  3. activehigh

    Context.ai OAuth Token Compromise

    Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.

    OtherAccount takeoverThird-party vendor breach
  4. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    npmOtherAccount takeoverCompromised packageMalicious commit