ShinyHunters Claims EY Breach via Supply-Chain Attack
ShinyHunters has claimed responsibility for the Ernst & Young breach first disclosed July 17, attributing entry to a supply-chain attack on EY systems.
ShinyHunters has claimed responsibility for the Ernst & Young data breach, per BleepingComputer. Attribution confidence: unconfirmed. ShinyHunters self-claim, not independently corroborated as of publication. Treat accordingly.
The group says it obtained credentials to some EY systems via a supply-chain attack. Which vendor in the chain, which tool, which credential path: unconfirmed.
Attribution update on the July 17 breach
EY disclosed a breach on July 17 involving unauthorized access to a third-party IT support ticket platform. Access window: March 28 – April 12, 2026. Detection: April 23 — eleven days after the window closed. No group had claimed it at disclosure. That gap is what today’s claim fills — partially.
ShinyHunters says the entry vector was a supply-chain attack yielding credentials to “some” EY systems. EY’s original disclosure named no vendor, no attacker, no affected individual count. That picture has not materially changed — ShinyHunters’ claim adds one new data point, not resolution.
Current ShinyHunters activity
The group has not been idle. Breach data from its operations is already funding sextortion campaigns at $2,000 Bitcoin per target. Microsoft documented three OAuth abuse paths the group ran against Salesforce-connected tenants in mid-July. Both campaigns extracted usable identity data from third-party platforms — the same category as EY’s support-ticket surface.
A supply-chain entry at EY — if the claim holds — fits that pattern. Third-party SaaS with elevated data access, compromised via a vendor in the chain rather than EY’s own infrastructure.
What remains open
- Which supply-chain vendor or tool served as the entry point.
- What systems beyond the support ticket platform were accessible.
- Affected individual count — EY still has not disclosed.
- Whether ShinyHunters will post the data publicly, issue a ransom demand, or both.
EY has not commented on the ShinyHunters attribution as of publication.
Practical read
The Experian monitoring EY offered to affected individuals — 24 months, enrollment deadline October 31, 2026 — covers identity fraud monitoring. It does not cover credential reuse from any password data that may have been in those ticket records. If your organization worked with EY on tax filings during the March–April window: audit service accounts and shared credentials that may have appeared in support tickets during that period.
Watch for a ShinyHunters data post or extortion demand. If data surfaces publicly, the scope will become clearer.
For ShinyHunters campaign context and the broader extortion landscape, see the Ransomware & Extortion hub.
Source: Ernst & Young data breach claimed by ShinyHunters extortion gang — BleepingComputer, July 27, 2026.
Found this useful? Share it.


