Cyber Resilience
← All news
Corroborated

Leak-site claim: shinyhunters lists Ernst & Young

Our takeShinyHunters lists Ernst & Young on its leak site, claiming a supply-chain breach that matches the firm's recent disclosure reported by Bleeping Computer. The claim is now corroborated. EY clients of all sizes should review shared data and watch for notifications.
Sources (4)
What this means for you — Security leader:If Ernst & Young handles audit, tax, or consulting work for you, request a formal incident notice covering which systems and which of your data classes are in scope. Review shared credentials, SSO trusts, and data rooms tied to EY engagements and rotate where appropriate.
What this means for you — Lean IT orgs:If you use Ernst & Young for accounting, tax, or advisory work, ask your contact whether any of your files or login details were involved. Treat unexpected emails or login prompts that claim to be from EY as suspicious until you verify out of band.
What this means for you — MSP:Identify clients with active EY audit or advisory relationships and pass along the claim with clear guidance that client impact is not yet established. Offer to review federation links, vendor-portal accounts, and shared mailboxes tied to those engagements.
What this means for you — Researcher:Corroborated ShinyHunters extortion claim against EY citing a supply-chain path to credentials. Watch for a victim statement, regulatory filing, or named upstream vendor, and compare any leaked samples to prior ShinyHunters sets.