Circuit Wire — a daily news update from the Circuit.

The extortion group ShinyHunters added Ernst & Young to its data leak site on Monday, July 27, and gave the firm until July 31 to make contact. The group told BleepingComputer that it obtained EY credentials through a supply-chain attack.

EY disclosed the underlying breach earlier this month. In its notification letter, the firm said a third-party information technology service management platform had been compromised. EY uses that platform to help its IT staff support teams doing tax work for clients, and support tickets submitted through it may include documents containing client tax information.

EY said it detected unusual activity on April 23 and later determined the attacker had access to the platform between March 28 and April 12, downloading multiple documents. The stolen documents contained personal and financial information included in or used to prepare tax filings.

The firm has not named the compromised support system, described the specific types of information exposed, or said how many people were affected. EY said it secured its systems, removed the unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.

No group had claimed the attack when EY first disclosed it. ShinyHunters now says the stolen credentials allowed it to reach EY's Jira, GitHub, and Azure environments, and that more data was taken than EY has acknowledged. The group would not identify the third party it says it compromised, and would not describe what it holds.

BleepingComputer said it has no way to verify those claims independently. Ernst & Young has not confirmed that ShinyHunters was behind the attack, and has not said whether it received an extortion demand.

The claim follows a run of similar listings by the same group. BleepingComputer has separately reported ShinyHunters claims involving Kodak, Medtronic, and the NAIC. Data taken in earlier ShinyHunters leaks has also been used to fuel sextortion email scams demanding around 2,000 dollars.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

Keep Reading