Breach Analysis·27 July 2026

Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm

The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira, GitHub and Azure environments, and to client tax documents.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Ernst & Young logo with breach alert overlay
Breach Analysis

Article record

Breach AnalysisCategory
27 July 2026Published
4 min readReading time
Mark FermorWritten by
Ernst & Young logo with breach alert overlay

Why it matters

What this means for organisations holding critical data

The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira, GitHub and Azure environments, and to client tax documents.

The ShinyHunters extortion gang has claimed responsibility for the recently disclosed Ernst & Young data breach, telling BleepingComputer that it obtained credentials to EY systems through a supply-chain attack against a third-party provider.

What Happened

Ernst & Young disclosed the breach earlier this month, confirming that a third-party IT service management platform used by its internal support teams was compromised. According to the firm''s breach notification, EY detected unusual activity on 23 April 2026 and determined that the attacker had access between 28 March and 12 April, downloading multiple documents from the platform.

On 27 July 2026, ShinyHunters added Ernst & Young to its data leak site and threatened to publish the allegedly stolen data if the firm did not respond by 31 July.

What Data Was Exposed

EY has confirmed that the compromised support tickets may contain client tax information, including personal and financial data used to prepare tax filings. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.

ShinyHunters has gone further, claiming to have used the stolen third-party credentials to reach into EY''s Jira, GitHub and Azure environments. EY has not confirmed that ShinyHunters was behind the attack, and the specific compromised support platform has not been named publicly.

Why This Matters

This is a textbook supply-chain compromise against a Big Four firm. The attackers did not need to breach EY directly. They breached a supplier and walked in with valid credentials. Once inside, the reach extended from a support ticketing tool into source code (GitHub), engineering workflow (Jira) and cloud infrastructure (Azure).

For professional services firms, the pattern is familiar. Client tax records, engagement letters, working papers and privileged correspondence increasingly sit inside SaaS tools operated by third parties. Every one of those tools is a credential surface an attacker can target, and every stolen credential is a route into the data your clients trust you to hold.

Professional Services Are a Permanent Target

Accountancy, legal and advisory firms are prized targets because they concentrate high-value data across many clients. A single compromised firm exposes the tax positions, deal papers and personal information of dozens or hundreds of underlying organisations and individuals.

The downstream risks include:

  • Client identity fraud using leaked tax and personal data to open credit lines or file fraudulent returns.
  • Business email compromise against clients and counterparties, informed by the actual engagement details taken from tickets and documents.
  • Regulatory exposure under UK GDPR, the SRA Standards and Regulations and the ICAEW Code of Ethics, where confidentiality is a professional obligation.
  • Loss of client trust, which for professional services firms is the entire business.

The Offline Alternative

Offline Secure Storage (OSS) is designed for the class of record most at risk in incidents like this: privileged client files, tax working papers, deal bibles and matter archives that do not need to sit in a live SaaS tenant. Files live on physically air-gapped hardware inside a monitored bunker, retrieved only through identity-verified sessions during defined access windows.

There is no persistent public endpoint, no shared cloud tenancy to misconfigure, and no third-party support platform holding a copy on your behalf. Credentials stolen from a supplier cannot be used to reach a system that is not on the network in the first place.

Key Takeaways

  • Supply-chain credentials are the new perimeter. A supplier''s support platform put a Big Four firm''s tax data at risk.
  • Blast radius is the real question. One stolen credential reportedly reached Jira, GitHub and Azure, not just the ticketing tool.
  • Client data belongs offline where possible. Archived matters and working papers do not need to be reachable 24/7 from every SaaS console.
  • Retrieval should be a verified session. Identity-checked access windows leave an auditable trail; a shared SaaS login does not.
  • Assume the supplier will be breached. Design so that a supplier compromise cannot cascade into privileged client records.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breach Analysis27 July 20264 min read

Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm

The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira, GitHub and Azure environments, and to client tax documents.

Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy