Ernst & Young data breach claimed by ShinyHunters extortion gang
ShinyHunters is extorting Ernst & Young over a breach it says started with credentials stolen via a supply-chain attack on a third-party support-ticket platform, then used to pivot into EY's own Jira, GitHub, and Azure environments between March 28 and April 12. The shape is the now-familiar ShinyHunters pattern from this year's Salesforce/Snowflake-adjacent campaigns: compromise a vendor's access layer, harvest live credentials, walk straight into source control and cloud infrastructure rather than malware-drop your way in. If your org shares SSO tokens or API credentials with third-party helpdesk/support-ticket vendors, rotate them now — EY says the incident is contained, but the gang's leak-site deadline is July 31.