The prolific cybercrime group ShinyHunters has claimed responsibility for a significant data breach at the global professional services firm Ernst & Young (EY). On July 29, 2026, the group added EY to its dark web data leak site, threatening to publish stolen data unless the firm begins negotiations by a July 31 deadline. ShinyHunters alleges they gained initial access through a supply-chain attack, which allowed them to compromise credentials and pivot into EY's internal Jira, GitHub, and Azure environments. This claim follows EY's own disclosure earlier in July about a breach at a third-party service management platform, which resulted in the exposure of sensitive client data, including Social Security numbers and financial information. EY has acknowledged the third-party breach but has not yet confirmed ShinyHunters' specific claims.
Threat Actor: ShinyHunters is a well-known and financially motivated extortion group that has been active for several years. They are known for large-scale data breaches targeting prominent companies and selling the stolen data on dark web forums. Recently, they have shifted more towards a double-extortion model, where they steal data and then threaten to leak it to pressure victims into paying a ransom.
Attack Vector: ShinyHunters claims the initial vector was a supply chain attack, a common TTP for the group. They compromised an unnamed third-party vendor to obtain EY credentials. This aligns with EY's earlier statement about a breach at a "service management platform" used by its IT teams for tax support.
Timeline:
Based on the available information, the attack likely followed these stages:
T1199 - Trusted Relationship): The attackers compromised a third-party service provider that had legitimate access to EY's environment. This is a classic supply chain attack vector.T1552 - Unsecured Credentials): ShinyHunters likely found and stole credentials within the compromised third-party environment, which they then used to access EY's internal systems.T1082 - System Information Discovery) to identify high-value data.T1530 - Data from Cloud Storage Object, T1567 - Exfiltration Over Web Service): The attackers located and downloaded sensitive documents from support tickets and other repositories. The data reportedly contained client names, addresses, Social Security numbers, and other financial data.T1486 - Data Encrypted for Impact - though not used here, the goal is similar: extortion): The final stage is extortion. By threatening to leak the data, ShinyHunters aims to coerce EY into paying a ransom.The breach has significant consequences for both EY and its clients:
No specific Indicators of Compromise were provided in the source articles.
To detect similar supply chain attacks, security teams should hunt for:
EY confirms ShinyHunters breach, specifying attackers accessed a third-party IT help-desk for over two weeks, exfiltrating client data from support tickets.
Enforce MFA for all accounts, especially third-party vendors, to prevent credential abuse.
Strictly segment and control network access for third-party vendors to prevent lateral movement.
Implement comprehensive logging and auditing of all third-party access and activity within the network.
Apply the principle of least privilege to all vendor accounts, ensuring they only have access to what is absolutely necessary.
Unauthorized access to a third-party service management platform used by EY begins.
The period of unauthorized access ends.
EY detects the anomalous activity in the third-party platform.
ShinyHunters adds EY to its data leak site and claims responsibility for the breach.
Deadline set by ShinyHunters for EY to begin negotiations.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.