---
title: "Ernst & Young Breach Claimed by ShinyHunters: S… | Firevault"
url: https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026
description: "The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira,…"
lang: en-GB
---

News · Breach Analysis · 27 July 2026

# Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm

The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira, GitHub and Azure environments, and to client tax documents.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fernst-young-shinyhunters-supply-chain-breach-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fernst-young-shinyhunters-supply-chain-breach-2026&text=Ernst%20%26%20Young%20Breach%20Claimed%20by%20ShinyHunters%3A%20Supply-Chain%20Attack%20Hits%20Big%20Four%20Firm%0A%0AThe%20ShinyHunters%20extortion%20gang%20has%20claimed%20responsibility%20for%20the%20Ernst%20%26%20Young%20breach%2C%20saying%20stolen%20third-party%20credentials%20opened%20the%20door%20to%20EY%27s%20Jira%2C%20GitHub%20and%20Azure%20environments%2C%20and%20to%20client%20tax%20documents.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fernst-young-shinyhunters-supply-chain-breach-2026

Image: Ernst & Young logo with breach alert overlay (https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg)

Ernst & Young logo with breach alert overlay

Why it matters

## What this means for organisations holding critical data

The ShinyHunters extortion gang has claimed responsibility for the recently disclosed Ernst & Young data breach (https://fire-vault.com/learn/breaches), telling BleepingComputer (https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/) that it obtained credentials to EY systems through a supply-chain attack against a third-party provider.

## What Happened

Ernst & Young disclosed the breach earlier this month, confirming that a third-party IT service management platform used by its internal support teams was compromised. According to the firm''s breach notification (https://oag.ca.gov/system/files/EY%20Notice%20Letter%20US%20General.pdf), EY detected unusual activity on 23 April 2026 and determined that the attacker had access between 28 March and 12 April, downloading multiple documents from the platform.

On 27 July 2026, ShinyHunters added Ernst & Young to its data leak site and threatened to publish the allegedly stolen data if the firm did not respond by 31 July.

## What Data Was Exposed

EY has confirmed that the compromised support tickets may contain client tax information, including personal and financial data used to prepare tax filings. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.

ShinyHunters has gone further, claiming to have used the stolen third-party credentials to reach into EY''s **Jira, GitHub and Azure environments**. EY has not confirmed that ShinyHunters was behind the attack, and the specific compromised support platform has not been named publicly.

## Why This Matters

This is a textbook supply-chain compromise against a Big Four firm. The attackers did not need to breach EY directly. They breached a supplier and walked in with valid credentials. Once inside, the reach extended from a support ticketing tool into source code (GitHub), engineering workflow (Jira) and cloud infrastructure (Azure).

For professional services firms, the pattern is familiar. Client tax records, engagement letters, working papers and privileged correspondence increasingly sit inside SaaS tools operated by third parties. Every one of those tools is a credential surface an attacker can target, and every stolen credential is a route into the data your clients trust you to hold.

## Professional Services Are a Permanent Target

Accountancy, legal and advisory firms are prized targets because they concentrate high-value data across many clients. A single compromised firm exposes the tax positions, deal papers and personal information of dozens or hundreds of underlying organisations and individuals.

The downstream risks include:

- **Client identity fraud** using leaked tax and personal data to open credit lines or file fraudulent returns.
- **Business email compromise** against clients and counterparties, informed by the actual engagement details taken from tickets and documents.
- **Regulatory exposure** under UK GDPR, the SRA Standards and Regulations and the ICAEW Code of Ethics, where confidentiality is a professional obligation.
- **Loss of client trust**, which for professional services firms is the entire business.

## The Offline Alternative

Offline Secure Storage (https://fire-vault.com/offline-secure-storage) (OSS) is designed for the class of record most at risk in incidents like this: privileged client files, tax working papers, deal bibles and matter archives that do not need to sit in a live SaaS tenant. Files live on physically air-gapped hardware inside a monitored bunker, retrieved only through identity-verified sessions during defined access windows.

There is no persistent public endpoint, no shared cloud tenancy to misconfigure, and no third-party support platform holding a copy on your behalf. Credentials stolen from a supplier cannot be used to reach a system that is not on the network in the first place.

## Key Takeaways

- **Supply-chain credentials are the new perimeter.** A supplier''s support platform put a Big Four firm''s tax data at risk.
- **Blast radius is the real question.** One stolen credential reportedly reached Jira, GitHub and Azure, not just the ticketing tool.
- **Client data belongs offline where possible.** Archived matters and working papers do not need to be reachable 24/7 from every SaaS console.
- **Retrieval should be a verified session.** Identity-checked access windows leave an auditable trail; a shared SaaS login does not.
- **Assume the supplier will be breached.** Design so that a supplier compromise cannot cascade into privileged client records.

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Custody**Named, access-controlled hardware in a Firevault Bunker

**Evidence**Access windows and retrieval events are recorded

**Separation**Physical isolation that satisfies offline copy requirements

**Jurisdiction**Stored where your regulatory position requires

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

Breach Analysis

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min
https://fire-vault.com/news/hcrg-care-group-children-records-cyber-attack-2026

Breach Analysis

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min
https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026

Breach Analysis

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min
https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026

Breach Analysis

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min
https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026#webpage",
    "url": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026",
    "name": "Ernst & Young Breach Claimed by ShinyHunters: S…",
    "description": "The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira,…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm",
        "item": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Ernst & Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm",
    "description": "The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young breach, saying stolen third-party credentials opened the door to EY's Jira, GitHub and Azure environments, and to client tax documents.",
    "url": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/5b822356-d947-44f2-88a0-f5d7d5f65621/ernst-young-shinyhunters-supply-chain-breach-2026-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-27T12:00:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Breach Analysis",
    "wordCount": 643,
    "keywords": "Ernst, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "The ShinyHunters extortion gang has claimed responsibility for the recently disclosed Ernst &amp; Young data breach, telling BleepingComputer that it obtained credentials to EY systems through a supply-chain attack against a third-party provider. What Happened Ernst &amp; Young disclosed the breach earlier this month, confirming that a third-party IT service management platform used by its interna",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```