The extortion group known as ShinyHunters has claimed responsibility for a data breach at Ernst & Young, saying it gained access to credentials for some of the professional services giant’s systems through a supply-chain attack, according to reporting by BleepingComputer.

The claim ties the incident to a recently disclosed breach at the firm. ShinyHunters asserted that the intrusion path did not begin with a direct assault on Ernst & Young’s own perimeter, but rather through a compromised third-party vendor whose access or systems provided a route into EY environments. Specific details about which vendor was involved have not been publicly confirmed, leaving an important gap for organizations trying to map their own exposure to the same supplier.

Supply-chain compromises of this kind remain one of the more difficult threats for large enterprises to contain. Even firms that invest heavily in internal security controls can be undermined when a trusted partner is breached and credentials, tokens, or integration pathways are abused. Professional services organizations such as Ernst & Young are especially sensitive targets: they routinely hold confidential client financials, deal information, and advisory materials, so any unauthorized access carries both operational and reputational risk.

ShinyHunters has built a pattern of pairing data theft with public pressure. By announcing breaches and threatening further disclosure, the group aims to force negotiations or amplify damage when victims resist. That playbook is particularly effective against well-known brands whose clients and regulators expect tight control over sensitive information. Whether the group ultimately publishes stolen material, sells it, or uses the claim purely for leverage often depends on how the victim responds and what evidence the attackers can produce.

For security and IT teams, the incident is a reminder that vendor risk management cannot be treated as a periodic checkbox exercise. Continuous assessment of third-party access, least-privilege integration design, and rapid revocation capabilities matter as much as internal hardening. Zero-trust approaches—verifying every request, limiting lateral movement, and assuming breach—are increasingly viewed as necessary rather than optional when partners and SaaS providers form part of the attack surface.

Incident response plans also need to account for scenarios in which the first alert comes from outside the organization, including from threat actors themselves or from journalists covering a claim. Clear internal escalation paths, pre-drafted external communications, and forensic readiness for credential-based and supply-chain intrusions can reduce chaos when a high-profile allegation surfaces.

The broader open-source and enterprise IT communities have watched similar supply-chain and credential-abuse campaigns intensify in recent years. Shared libraries, managed service providers, and identity integrations create efficiency—but they also concentrate risk. When a single upstream compromise can unlock access at a firm of Ernst & Young’s scale, the case for stronger software supply-chain transparency, software bills of materials, and continuous monitoring of third-party connections becomes harder to ignore.

As of the BleepingComputer report, independent confirmation of the full scope of data involved and the precise vendor pathway remains limited. Organizations that work with Ernst & Young or with overlapping service providers will want to watch for official statements from the firm and for any indicators of compromise that may emerge as the investigation continues. Until more technical detail is available, the practical takeaway is straightforward: treat third-party credentials and integrations as high-value assets, and assume that attackers will look for the weakest trusted link rather than the strongest front door.


根據 BleepingComputer 的報導,名為 ShinyHunters 的勒索集團已聲稱對安永(Ernst & Young)的數據洩露事件負責,表示透過供應鏈攻擊,取得了這間專業服務巨頭部分系統的憑證。

該聲稱將事件與該公司最近披露的洩露事件聯繫起來。ShinyHunters 斷言,入侵路徑並非直接攻擊安永自身的網絡邊界,而是透過一個已遭入侵的第三方供應商,其存取權限或系統為進入安永環境提供了途徑。關於涉及哪家供應商的具體細節尚未公開確認,令試圖評估自身對同一供應商風險敞口的組織出現重要缺口。

這類型的供應鏈入侵仍然是大型企業最難以遏制的威脅之一。即使在內部安全控制投入大量資源的企業,一旦受信任的合作夥伴遭到入侵,其憑證、令牌或整合途徑被濫用,安全防線亦可能被瓦解。像安永這類專業服務機構尤其屬於敏感的攻擊目標:它們經常持有客戶機密財務資料、交易資訊及諮詢材料,因此任何未經授權的存取都會帶來營運及聲譽風險。

ShinyHunters 已建立一套將數據竊取與公眾施壓結合的模式。透過宣布入侵事件並威脅進一步公開資料,該集團旨在迫使受害者談判,或在受害者抗拒時放大損失。這套策略對於那些客戶及監管機構都期望其嚴格控制敏感資訊的知名企業特別有效。該集團最終是公佈、出售被竊資料,抑或純粹利用這項聲稱作為談判籌碼,往往取決於受害者的回應以及攻擊者能夠提供的證據。

對於安全及 IT 團隊而言,這次事件提醒我們,供應鏈風險管理不能被視為一項定期的「勾選」工作。對第三方存取權限的持續評估、最低權限的整合設計,以及快速撤銷權限的能力,與內部安全加固同樣重要。當合作夥伴及 SaaS 供應商成為攻擊面的一部分時,零信任架構——驗證每一個請求、限制橫向移動、並假定已被入侵——正越來越被視為必要而非可選。

事件應對計劃亦需要考慮到首次警報可能來自組織外部的情況,包括來自威脅行為者本身或報導該項聲稱的記者。清晰的內部升級路徑、預先擬定的外部通訊,以及針對基於憑證及供應鏈入侵的取證準備,都可以在備受矚目的指控浮現時減少混亂。

廣泛的開源及企業 IT 社區近年來已目睹類似供應鏈及憑證濫用攻擊活動日益加劇。共用函式庫、託管服務提供商及身份整合創造了效率——但亦集中了風險。當單一上游入侵可以解鎖對安永這種規模的公司的存取權限時,要求更強軟件供應鏈透明度、軟件物料清單(software bills of materials)以及對第三方連接的持續監控的理由就變得更難以忽視。

截至 BleepingComputer 報導,獨立確認涉及數據的全部範圍以及確切供應商路徑仍然有限。與安永或重疊服務提供商合作的組織將會留意該公司的官方聲明,以及隨著調查持續可能出現的任何入侵指標。在更多技術細節公佈之前,實際要點很簡單:將第三方憑證及整合視為高價值資產,並假定攻擊者會瞄準最弱的信任環節,而非最堅固的正門。

新聞來源 / Original News Source