Home/News/ShinyHunters Claims Ernst & Young Data Breach
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

ShinyHunters Claims Ernst & Young Data Breach

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed data breach affecting Ernst & Young (EY), a global professional services firm. In a post on a dark web forum, the group stated that they obtained credentials for some of EY's systems through a supply-chain attack. This method involves compromising a less secure third-party vendor or software that EY uses, thereby gaining indirect access to EY's network and data. The exact nature and scope of the data compromised have not yet been fully disclosed by EY, nor has the specific third-party vendor that was allegedly targeted in the supply-chain attack.

Ernst & Young confirmed the security incident in an earlier statement, acknowledging that unauthorized access to certain systems had occurred. The company stated that it had taken immediate steps to secure its environment and launched an investigation into the incident. EY also indicated that it was working with external cybersecurity experts to assess the situation and that it would notify any affected individuals or regulatory bodies as required. The firm has not yet provided specific details regarding the type of data accessed or the number of individuals potentially impacted by the breach. The claim by ShinyHunters adds a layer of attribution to the incident, as the group is known for extorting companies after exfiltrating their data.

ShinyHunters has a history of targeting large organizations and leaking or threatening to leak sensitive data unless a ransom is paid. Their modus operandi often involves exploiting vulnerabilities or using stolen credentials to gain access to corporate databases. The group's claim of a supply-chain attack suggests a sophisticated approach, as these attacks can be more challenging to detect and prevent than direct intrusions. The cybersecurity landscape has seen a significant rise in supply-chain attacks, which leverage the interconnectedness of businesses and their reliance on external software and service providers. These attacks can have far-reaching consequences, as a single compromise can impact numerous downstream organizations.

The incident at Ernst & Young, a firm that advises many other businesses on risk management and cybersecurity, highlights the persistent threats faced by even the most security-conscious organizations. The professional services sector, in particular, handles vast amounts of sensitive client data, making it an attractive target for cybercriminals. The ongoing investigation by EY and its cybersecurity partners will be crucial in determining the full impact of the breach and the specific vulnerabilities exploited. The company's commitment to transparency and timely notification will be key in managing the fallout and rebuilding trust with its clients and stakeholders.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next