Your Accountant Just Got Hacked. And Your Tax Records Went With Them.
ShinyHunters breached Ernst & Young through a third-party support platform, stealing client tax records including SSNs and financial account numbers. Here's what every business leader needs to know.
Today is July 31, 2026. That date matters, because it's the deadline ShinyHunters — one of the world's most prolific data extortion gangs — gave Ernst & Young to negotiate or watch their clients' tax records get dumped on the dark web.
Let that sink in. One of the Big Four global accounting firms. The firm that thousands of corporations trust with their most sensitive financial data. Breached through a third-party support ticketing platform. And the stolen data? Tax records containing Social Security numbers, bank account details, credit and debit card information, and the financial information used to prepare filings for EY's clients worldwide.
This isn't just an EY story. It's a story about how companies get breached today — and why it's rarely through the front door.
What Actually Happened
Here's what we know. Between March 28 and April 12, 2026, an unauthorized third party accessed an IT service management platform that EY uses internally to support its tax-related work for clients. Think of it as the software EY's IT help desk uses when someone submits a support ticket about a tax filing system. Except those support tickets often had client tax documents attached.
EY detected the anomalous activity on April 23 — eleven days after the attacker had already left. The intruder got in, downloaded what they wanted, and walked out. The alarm didn't go off until after they were gone.
EY began notifying state attorneys general in July — more than three months after the intrusion ended. ShinyHunters then claimed responsibility on July 27, asserting they gained entry through a supply-chain attack and used stolen credentials to access EY's Jira, GitHub, and Azure environments. They set a July 31 deadline to publish everything unless EY reached out.
As of this writing, no stolen data has been published. But the clock has run out.
The Part That Should Worry You Most
EY didn't get breached because of a sophisticated nation-state attack on their core systems. They got breached because a third-party platform — an external vendor tool — had credentials that shouldn't have been accessible, held documents that shouldn't have been there, and wasn't monitored closely enough to catch an intruder for eleven days.
This pattern is becoming the playbook. The Stadler Rail breach in July: supplier data exchange platform. The Accenture breach this month: source code and credentials stolen. The Abbott breach: compromised SSO account from a vishing call. The Klue breach earlier this year: OAuth tokens from a third-party vendor, hitting nearly 200 companies simultaneously.
The attackers figured something out that many organizations haven't fully internalized yet: your security is only as strong as the weakest platform you've connected to your data.
EY is, by every measure, a sophisticated organization. They have full-time security teams. They have incident response procedures. They work with independent cybersecurity firms. And they still had a third-party vendor platform holding client tax documents — including SSNs and financial account numbers — that an attacker could walk into and download without triggering an alert for two weeks.
If it can happen to EY, it can happen to your accountant, your payroll processor, your benefits administrator, your IT help desk vendor, or your legal firm.
Three Questions Every Business Leader Should Ask Right Now
You may not be EY. But you likely share the same exposure pattern.
First: What third-party platforms hold your sensitive data? Not just your vendors — but the vendors' platforms. The tools your accountant uses to manage your tax filings. The software your HR firm uses to process payroll. The ticketing system your managed IT provider uses to track support requests. Every one of those platforms is a potential entry point. Do you know what data lives inside them? Do you know who has access? Do you know how quickly you'd detect unauthorized access?
Second: How long would it take you to detect an intruder? EY's gap was eleven days between intrusion ending and detection. That means the attacker had complete access for the full two weeks of the breach window with no interference. In cybersecurity terms, that's called dwell time — and longer dwell time means more data stolen, more systems mapped, more credentials harvested. The industry average for dwell time before detection is measured in days to weeks. Most organizations don't know theirs.
Third: What happens when your vendor gets breached? This is the question most business continuity plans don't answer. Your contracts with vendors probably have data protection language. But do those contracts require timely breach notification? Do they give you audit rights? And if your vendor's platform gets compromised, do you have a clear list of what data was stored there, who it belongs to, and what your notification obligations are?
These aren't theoretical questions. With the EY breach, affected clients are being offered 24 months of credit monitoring. That's the after-the-fact remedy. The before-the-fact protection — knowing your third-party exposure map — is what actually prevents the damage.
What Good Looks Like
Organizations managing this risk well do a few things consistently:
They maintain a living inventory of third-party vendors and the data those vendors can access. Not just a contract file — an actual map of what data flows where, who has credentials, and what platforms hold what information.
They apply least-privilege principles beyond their own systems. If a vendor platform doesn't need to hold sensitive documents, those documents shouldn't be there. Support tickets don't need to contain full tax returns. They can reference them, or use a more controlled file exchange.
They require vendors to meet minimum security standards — not just accept vendor assurances, but ask for SOC 2 reports, conduct periodic security reviews, and build breach notification requirements into contracts.
And they monitor for anomalous access — even on third-party platforms. Not all of them offer this capability, which itself should be a selection criterion.
The Bigger Picture
We've now watched ShinyHunters breach Medtronic (3.8 million patients, vishing entry), Abbott Laboratories (30 million records claimed), and now Ernst & Young — all in 2026. The pattern is consistent: find a peripheral platform, grab credentials, move laterally, exfiltrate data.
The perimeter is irrelevant when the attack enters through a legitimate vendor.
If you're a CEO or business owner reading this, here's the honest assessment: your biggest cyber risk in 2026 probably isn't a sophisticated zero-day exploit against your core systems. It's a third-party platform you haven't audited in two years that's holding data you forgot was there.
That's what the EY breach is telling every business leader today. The question is whether you hear it before or after the breach notification letter arrives.
---
TrustPoint Cyber helps organizations map their third-party exposure, build vendor security programs, and reduce the risk of supply-chain breaches. If you'd like to understand your current exposure, [contact us](/contact) to start the conversation.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.