The extortion group ShinyHunters has publicly named professional services firm Ernst & Young (EY) on its leak site, alleging a data breach and setting a July 31 deadline for contact before publishing stolen material. According to a report by Security Affairs, the group claims to hold sensitive client-related data, specifically threatening to release what it describes as tax records.

The listing represents an extortion campaign in the public phase, with the group using the deadline as leverage. Independent verification of the breach's scope, the nature of any exfiltrated files, or the accuracy of the "tax records" description has not been established. Those details rest entirely on the group's own statements and should be considered unverified allegations.

EY had not issued a public response to the claim or ultimatum at the time of reporting. Such silence is standard incident-response practice, allowing organisations to investigate internal systems, assess legal and regulatory obligations, and coordinate with authorities before making a public statement. Until an official response is provided, the public record is dominated by the criminal group's assertions.

ShinyHunters has a documented history of high-profile breach claims paired with leak-site extortion. The group's typical pattern involves asserting access to large volumes of data, publishing proof samples on a dark-web portal, and imposing short deadlines for payment or negotiation. Whether the EY listing stems from a genuine intrusion, recycled credentials, or an inflated claim remains an open question, resolvable only through forensic investigation and a formal corporate response.

For the broader industry, the incident highlights how professional services firms are targeted due to a concentration of trust. Companies like EY handle tax, audit, and advisory material for thousands of clients across sectors. Compromising a single provider creates leverage over many downstream organisations, making such firms high-value targets for extortion groups who understand this dynamic and attack reputational and client relationships as directly as they target databases.

Monitoring the situation will focus on several key signals: whether EY confirms or denies unauthorised access; whether sample data appears on the leak site before or after the July 31 deadline; and any involvement from regulators or law-enforcement agencies. Until then, the essential distinction must be maintained between the confirmed fact—a named extortion group has targeted EY and set a public deadline—and the unproven assertions about what data may have been taken.

The event serves as a reminder for organisations relying on third-party professional services to review and strengthen incident-notification clauses, business-continuity plans, and vendor security assessments. How EY and the wider industry respond to this allegation will be significant beyond the immediate claim.


勒索組織 ShinyHunters 已在其資料外洩網站上公開點名專業服務公司安永(EY),指控其發生資料外洩事件,並設定七月三十一日為最後期限,要求對方聯絡,否則將公開竊取的資料。據《Security Affairs》報導,該組織聲稱持有涉及客戶的敏感資料,具體威脅將公布其所稱的稅務記錄。

此公告代表勒索活動進入公開階段,該組織利用最後期限作為施壓籌碼。目前尚未有獨立核實證實外洩事件的規模、任何被竊文件的性質,或「稅務記錄」描述的準確性。這些細節完全基於該組織的單方面聲明,應被視為未經證實的指控。

截至報導時,安永尚未針對該指控或最後通牒作出公開回應。此類沉默是標準的事後處理做法,讓組織得以調查內部系統、評估法律及監管義務,並在公開聲明前與有關當局協調。在官方回應發布前,公開記錄主要由犯罪組織的陳述主導。

ShinyHunters 有記錄顯示其過往涉及多宗高調資料外洩聲明及利用資料外洩網站進行勒索。該組織的典型模式包括宣稱存取大量資料、在暗網平台公布樣本,並設定短期期限要求付款或進行談判。安永的公告是否源於真實入侵、重複使用的憑證,抑或誇大的指控,仍是一個待解問題,只能透過鑑證調查及正式的企業回應來釐清。

對整體行業而言,此事件凸顯了專業服務公司因信任集中而成為目標。像安永這樣的公司,為跨行業的數千家客戶處理稅務、審計及顧問事務。入侵單一供應商便能對眾多下游組織形成施壓,使這類公司成為勒索組織眼中的高價值目標。這些組織深諳此道,攻擊聲譽與客戶關係的直接程度,猶如攻擊資料庫一般。

監察事態發展將聚焦幾個關鍵信號:安永是否確認或否認未經授權的存取;樣本資料是否在七月三十一日期限前或後出現在外洩網站;以及監管機構或執法部門的介入情況。在此之前,必須區分已確認的事實——一個具名的勒索組織已針對安永並設定公開期限——與關於可能被竊資料的未經證實說法。

此事件提醒依賴第三方專業服務的組織,應檢視並加強事故通知條款、業務連續性計劃及供應商安全評估。安永及整個行業如何回應此指控,其意義將超越眼前的單一事件。

新聞來源 / Original News Source