Ernst & Young data breach claimed by ShinyHunters extortion gang
Summary
The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, stating they gained access through a supply-chain attack that compromised credentials. The attackers are reportedly seeking an undisclosed ransom.
IFF Assessment
FOE
This news indicates a successful attack and potential data exfiltration, representing a win for threat actors and a setback for defenders.
Defender Context
This incident highlights the persistent threat of supply-chain attacks and the need for robust credential management and supply-chain risk assessments. Defenders should be vigilant about monitoring for unauthorized access and verifying the security posture of third-party vendors.