Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

ShinyHunters Claims Ernst & Young Hack

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ernst & Young data breach

The infamous ShinyHunters extortion group has claimed responsibility for the recently disclosed Ernst & Young (EY) data breach.

Earlier this month, the professional services giant reported to the Attorney General’s Offices in several states that hackers stole personal and financial information from a third-party service management platform used to support tax-related work.

Between March 28 and April 12, the company said, the attackers downloaded the tax-related documents of Ernst & Young clients that were included in support tickets submitted through the platform.

Client names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used for tax filings were compromised in the data breach.

The company is providing the potentially impacted individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services.

Ernst & Young has not shared details on the number of potentially affected individuals, nor did it say who was behind the attack. The company has not responded to a SecurityWeek inquiry on the matter.

Advertisement. Scroll to continue reading.

On Monday, ShinyHunters added the professional services firm to its Tor-based leak site, threatening to release all the stolen data if Ernst & Young does not make contact by July 31.

With a history of following through on its threats, the extortion group has been linked to multiple high-profile data breaches recently, including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns.

Related: Origin Energy Data Breach Affects 900,000 Australians

Related: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Related: MCBS Data Breach Affects 1.2 Million Individuals

Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.