From the Coupang Data Breach to Ernst & Young
The ShinyHunters extortion gang has put Ernst & Young on its leak site, claiming responsibility for a breach that gave them access to the firm's Jira, GitHub, and Azure environments through a supply-chain attack. They've set a July 31, 2026 deadline for EY to contact them — or face public release of allegedly stolen data. EY hasn't confirmed the claim. ShinyHunters hasn't proved it. Nobody has.
What we do know comes from the firm's own disclosure: between March 28 and April 12, 2026, an attacker accessed a third-party IT service management platform used by EY's support teams, downloading documents that may have contained client tax information. The company detected unusual activity on April 23, secured its systems, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring through Experian.
That's the official story. ShinyHunters is telling a different one — one that suggests the breach went much deeper than EY publicly acknowledged, and that the attack vector was a compromised third-party vendor, not a direct breach of EY's infrastructure.
Whether either side is telling the complete truth remains unclear. What's clear is that ShinyHunters' modus operandi has become predictable, even if their targets aren't.
What the Coupang Data Breach and Ernst & Young Have in Common
The coupang data breach, the Ernst & Young disclosure, and a growing list of high-profile intrusions this year all share a common thread: attackers exploiting the SaaS layer, not the perimeter.
ShinyHunters doesn't break through firewalls. They walk through doors organizations left open — OAuth tokens that should have expired, misconfigured Salesforce portals, supply-chain integrations trusted but never audited. They've breached Salesforce, Google, Workday, Louis Vuitton, Coinbase, Qantas, and now, allegedly, Ernst & Young. All within roughly a twelve-month window.
The coupang data breach followed a similar pattern, relying on device code phishing and vishing to bypass traditional security controls. The Ernst & Young incident appears to have used a compromised third-party support ticket system as the initial foothold. Different entry points. Same underlying vulnerability: SaaS environments with too much trust and too little visibility.
"ShinyHunters don't hack through walls," one security analysis noted. "They exploit the gap between what organizations assume their SaaS environment looks like and what it actually is."
How ShinyHunters Got Into Ernst & Young
According to the threat actor's claims to BleepingComputer, ShinyHunters obtained EY credentials through a supply-chain attack — compromising a third-party vendor that EY's IT personnel use to manage support tickets. Those stolen credentials allegedly granted access to Jira, GitHub, and Azure environments, giving the group a foothold deep inside EY's operational infrastructure.
The attacker wouldn't identify the compromised third party. They wouldn't disclose exactly what data was stolen beyond confirming that EY's acknowledged breach was real, and suggesting there was more.
Ernst & Young has not confirmed that ShinyHunters was behind the attack. BleepingComputer could not independently verify the threat actor's claims. The firm declined to name the compromised support system or disclose how many people were affected.
That silence is telling. It leaves the question open whether ShinyHunters is telling the truth, exaggerating, or fabricating. But the timeline checks out: EY disclosed the breach in July 2026, and ShinyHunters added EY to its leak site shortly after, threatening to release data if the firm didn't respond by July 31, 2026.
ShinyHunters' Playbook: Five Ways They Get In
ShinyHunters operates like a business, pricing models, negotiation playbooks, affiliate programs. Their attack methods are documented, repeatable, and increasingly sophisticated:
OAuth token abuse. Compromise a single integration in your SaaS chain, steal the OAuth token it holds, and use that token to impersonate a legitimate user across every platform it has access to. Because OAuth tokens represent pre-authorized access, they bypass multi-factor authentication entirely. This was central to the Salesloft Drift campaign, which gave ShinyHunters access to 760 downstream Salesforce customer organizations in a single operation.
SaaS misconfiguration exploitation. Exploit overly permissive guest user profiles on Salesforce Experience Cloud sites or misconfigured Google Workspace OAuth permissions. No vulnerability required, just an open door.
Supply chain compromise. Breach one vendor that hundreds of organizations trust, and collect the access automatically. The Salesloft Drift breach affected Cloudflare, Zscaler, Palo Alto Networks, and Google.
Insider recruitment. Actively recruit corporate insiders, contractors, employees, service desk staff, through Telegram channels, offering financial rewards for access credentials to Okta, Citrix VPN, Microsoft SSO, GitHub, and GitLab.
AI-powered vishing. Use legitimate AI voice platforms to impersonate IT helpdesk staff, guiding victims through social engineering to approve attacker-controlled applications. This was the method behind the Workday breach.
Each method is distinct. All of them are common. And every one of them is addressable, if organizations actually look.
Why This Matters for 2026
The 2026 breach landscape tells a clear story: ShinyHunters has become arguably the most consequential financially motivated hacking collective operating today. Google tracks their activity under multiple threat clusters, UNC6040, UNC6240, and UNC6661, allowing researchers to differentiate between specific campaigns within the broader organization.
They've compromised over 400 organizations in 2026 alone, stealing data on 400 million people across 40+ breaches. Their targets span retail, technology, finance, aviation, automotive, and now, allegedly, professional services.
Arrests have slowed them temporarily, a French programmer was sentenced to three years in prison in 2024, and four additional suspected members were arrested in France in 2025, but operations have continued through and after each law enforcement action.
The Ernst & Young claim, whether verified or not, fits squarely within this pattern. ShinyHunters targets organizations with large customer databases, high-net-worth clientele, and cloud-based platforms that aggregate data from multiple organizations. A single breach yielding dozens of downstream victims. That's their business model.
What Organizations Can Do
The attack surface ShinyHunters exploits is addressable. OAuth apps can be inventoried and governed. Misconfigurations can be detected before attackers find them. Insider risk can be quantified and managed. Lateral movement can be detected and stopped mid-chain.
Organizations need real-time visibility into every OAuth application connected to their SaaS ecosystem, every app, every permission scope, every user who authorized it. They need continuous scanning of SaaS configurations against security best practices, flagging drift before attackers find it. They need behavioral monitoring that establishes baselines for every user and flags deviations, bulk downloads, off-hours access, unusual file sharing patterns.
The gap between what organizations think their SaaS environment looks like and what it actually is where ShinyHunters operates. Closing that gap isn't optional anymore. It's the difference between a security incident and a headline.
Whether Ernst & Young was actually breached by ShinyHunters remains unverified. But the pattern is clear, the tactics are documented, and the organizations that fail to act on what we know about ShinyHunters' methods in 2026 are simply waiting for their own name to appear on a leak site.
Sources: BleepingComputer, DoControl, State of Surveillance
Related: Inside the Coupang Data Breach, Coupang's Record $409M Data Breach Fine
twentyTaskId: c1bffaf0-2990-421b-b9cb-0d95e2d9cf5f