Ernst & Young has confirmed that attackers stole client tax information after breaking into a third-party support-ticket system used by its IT staff. The company says unauthorised access ran from 28 March to 12 April this year and went undetected until 23 April — nearly two weeks after the intrusion had already ended. The stolen material included personal and financial data attached to support tickets used to prepare client tax filings.
On 27 July, the ShinyHunters extortion gang claimed responsibility on its dark-web leak site, telling researchers it reached EY's environment through a supply-chain credential compromise that gave it a foothold in Jira, GitHub, and Azure. The group posted a "final warning": hand over a ransom by 31 July or it will publish everything it took. EY has not confirmed how many people are affected or which specific platform was compromised, but it has started notifying clients and is offering 24 months of identity monitoring through Experian, with enrolment open until the end of October.
What this means for your business
- The weak point wasn't EY's own systems — it was a support tool plugged into them. A ticketing platform used for routine IT requests became the door into client tax files. Any tool where staff attach real client documents "just for this ticket" is now part of your sensitive-data footprint, whether it's formally treated that way or not.
- Stolen credentials from one breach can unlock several more. ShinyHunters says a single supply-chain credential compromise gave it reach into three separate internal platforms. If a vendor or contractor account is compromised, check what else that account's login could touch before assuming the damage is contained to one system.
- Two weeks of undetected access is common, not unusual. EY's own timeline shows attackers were inside for roughly two weeks before anyone noticed. If nobody would notice unusual activity on your admin or support tools within a similar window, that's worth fixing before it's tested for real.
- Have a plan for "pay or we publish" before it lands in your inbox. A firm this size still had to scramble to notify clients and stand up monitoring after the fact. Decide in advance who gets called, what gets disclosed, and by when — not during a countdown someone else set.
Attach fewer real client documents to support requests than you think you need to, keep a running list of which third-party tools can see client data, and make sure someone would actually notice if one of those tools started behaving oddly.