← BACK TO FEED
data breachShinyHuntersErnst & Youngransomwaretax data

ShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach

Ernst & Young (EY) suffered a data breach between March 28 and April 12, in which hackers stole sensitive client information — including Social Security numbers, account numbers, and tax-related documents — from a third-party service management platform. The notorious extortion group ShinyHunters has since claimed responsibility, adding EY to its leak site and threatening to release the stolen data if the firm does not make contact by July 31. EY has not disclosed the number of affected individuals or confirmed the attacker's identity, but is offering impacted clients 24 months of free credit monitoring and identity protection services.

ShinyHunters, the extortion crew responsible for a growing list of high-profile breaches, has now set its sights on Ernst & Young. The group added the Big Four firm to its Tor-based leak site on Monday, giving EY until July 31 to make contact before the stolen data gets dumped publicly.

EY had already disclosed the breach to several state Attorney General offices earlier this month. The attack targeted a third-party service management platform used for tax-related support work, and it wasn't a quick smash-and-grab. Between March 28 and April 12, attackers quietly pulled down client tax documents that had been submitted through the platform's support ticket system.

The haul is about as bad as it gets for a tax services context. Client names, home addresses, Social Security numbers, account numbers, and credit and debit card details were all in the mix. Essentially everything someone would need to cause serious financial damage to the individuals involved.

EY is offering affected individuals 24 months of free credit monitoring, identity monitoring, and identity restoration services. The standard post-breach goodwill package. The firm hasn't said how many people are affected, hasn't named any suspects, and didn't respond to press inquiries. So that's going well.

ShinyHunters has a track record of actually following through on its threats, which makes the July 31 deadline worth taking seriously. The group has been tied to breaches at the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns, among others. This isn't a group that makes empty gestures.

The breach also raises the familiar and uncomfortable question about third-party platforms. EY's own systems may be perfectly hardened, but the moment sensitive client data flows through an external support tool, it's only as secure as whoever built and maintains that tool. Tax documents containing Social Security numbers sitting in support tickets on a third-party platform is, to put it charitably, a challenging architecture from a security perspective.

WATCH THE SHORT
READ NEXT
EY Breach Exposes Client Tax Data Including SSNs and Card NumbersShinyHunters Breach Exposes Data of 3.8 Million Medtronic PatientsMedtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach