Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

ShinyHunters Claims Ernst & Young Hack

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ernst & Young data breach

The infamous ShinyHunters extortion group has claimed responsibility for the recently disclosed Ernst & Young (EY) data breach.

Earlier this month, the professional services giant reported to the Attorney General’s Offices in several states that hackers stole personal and financial information from a third-party service management platform used to support tax-related work.

Between March 28 and April 12, the company said, the attackers downloaded the tax-related documents of Ernst & Young clients that were included in support tickets submitted through the platform.

Client names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used for tax filings were compromised in the data breach.

The company is providing the potentially impacted individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services.

Ernst & Young has not shared details on the number of potentially affected individuals, nor did it say who was behind the attack. The company has not responded to a SecurityWeek inquiry on the matter.

Advertisement. Scroll to continue reading.

On Monday, ShinyHunters added the professional services firm to its Tor-based leak site, threatening to release all the stolen data if Ernst & Young does not make contact by July 31.

With a history of following through on its threats, the extortion group has been linked to multiple high-profile data breaches recently, including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns.

Related: Origin Energy Data Breach Affects 900,000 Australians

Related: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Related: MCBS Data Breach Affects 1.2 Million Individuals

Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.