:

SHINYHUNTERS CLAIMS ERNST & YOUNG DATA BREACH

AI DESK1 MIN READ
MON, JUL 27, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, stating it obtained system credentials through a supply-chain attack.

ShinyHunters, known for extortion-focused cyber operations, disclosed the breach and claimed access to EY infrastructure via compromised credentials from a third-party supplier. The group's involvement suggests a targeted approach rather than opportunistic hacking. Ernst & Young is one of the Big Four accounting and consulting firms, making the breach significant for its potential access to sensitive client data. The supply-chain attack vector indicates attackers exploited a weaker link in EY's network defenses rather than directly targeting the firm's primary systems. ShinyHunters typically operates as an extortion gang, threatening to leak stolen data unless demands are met. The group has claimed responsibility for breaches at multiple organizations in recent years. EY has not yet provided detailed comment on the breach scope, affected systems, or client impact. The firm's response and any ransom negotiations remain unclear.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cisco has issued a warning about a high-severity denial-of-service vulnerability affecting its Secure Firewall ASA and Threat Defense (FTD) software. The flaw is being actively exploited in the wild to remotely crash affected devices.

JUST NOWSecurity Desk

Security researchers have demonstrated methods to extract reasoning traces from proprietary large language model APIs, potentially exposing internal model behaviors and decision-making processes that companies intended to keep private.

JUST NOWAI Desk

British Transport Police have expanded live facial recognition (LFR) technology to London Underground stations as part of an ongoing trial. The system scans passenger faces to identify individuals on watchlists.

JUST NOWIndustry Desk

The FBI has issued an alert about cybercriminals hacking into personal accounts to steal intimate images for extortion purposes. The campaigns target both adults and minors.

JUST NOWSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.