ShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach
ShinyHunters, the extortion crew responsible for a growing list of high-profile breaches, has now set its sights on Ernst & Young. The group added the Big Four firm to its Tor-based leak site on Monday, giving EY until July 31 to make contact before the stolen data gets dumped publicly.
EY had already disclosed the breach to several state Attorney General offices earlier this month. The attack targeted a third-party service management platform used for tax-related support work, and it wasn't a quick smash-and-grab. Between March 28 and April 12, attackers quietly pulled down client tax documents that had been submitted through the platform's support ticket system.
The haul is about as bad as it gets for a tax services context. Client names, home addresses, Social Security numbers, account numbers, and credit and debit card details were all in the mix. Essentially everything someone would need to cause serious financial damage to the individuals involved.
EY is offering affected individuals 24 months of free credit monitoring, identity monitoring, and identity restoration services. The standard post-breach goodwill package. The firm hasn't said how many people are affected, hasn't named any suspects, and didn't respond to press inquiries. So that's going well.
ShinyHunters has a track record of actually following through on its threats, which makes the July 31 deadline worth taking seriously. The group has been tied to breaches at the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns, among others. This isn't a group that makes empty gestures.
The breach also raises the familiar and uncomfortable question about third-party platforms. EY's own systems may be perfectly hardened, but the moment sensitive client data flows through an external support tool, it's only as secure as whoever built and maintains that tool. Tax documents containing Social Security numbers sitting in support tickets on a third-party platform is, to put it charitably, a challenging architecture from a security perspective.