Ernst & Young data breach claimed by ShinyHunters extortion gang

Summary

The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, stating they gained access through a supply-chain attack that compromised credentials. The attackers are reportedly seeking an undisclosed ransom.

IFF Assessment

FOE

This news indicates a successful attack and potential data exfiltration, representing a win for threat actors and a setback for defenders.

Defender Context

This incident highlights the persistent threat of supply-chain attacks and the need for robust credential management and supply-chain risk assessments. Defenders should be vigilant about monitoring for unauthorized access and verifying the security posture of third-party vendors.

Read Full Story →