We Said This Morning That Claiming a Breach Isn't Proof. ShinyHunters Just Claimed Ernst & Young — and This One Passes the Test.
- Patrick Duggan
- 1 day ago
- 4 min read
This morning we published a piece arguing that a crew claiming a breach is not evidence the crew did it, because ShinyHunters has become a valuable enough brand to wear. The clean case was Vercel, where an attacker claimed to be ShinyHunters and ShinyHunters said it wasn't them.
Hours later ShinyHunters added Ernst & Young to its leak site, claiming it took EY credentials through a supply-chain attack and reached Jira, GitHub, and Azure. The deadline to make contact is July 31 — four days out.
So let's use our own framework on a live case, because a rule you only apply when it's convenient isn't a rule.
The test is tradecraft, not the claim
The argument this morning was never "believe nobody." It was: check whether the claim matches the crew's actual tradecraft. Vercel failed that test in the loudest way possible — the crew being credited publicly disowned it.
This one passes.
Our own adversary profile for ShinyHunters, written in May, describes the group's defining technique as breaching cloud SaaS platforms to reach the data of everyone downstream. Not phishing an employee laptop. Not ransomware. Compromise the platform that many organizations trust, then harvest.
EY's disclosure describes exactly that shape from the victim side: a third-party IT service management platform used by EY's own IT staff was compromised. The attacker was inside from March 28 to April 12, and EY detected it on April 23. Support tickets submitted through that platform may contain client tax information.
A third-party ITSM platform, supply-chain credentials, downstream client data. That is ShinyHunters' signature pattern, and it is the pattern we documented before this incident existed.
That still is not confirmation. EY has not confirmed ShinyHunters was behind it, and ShinyHunters claims more data than EY has disclosed — a standard extortion-pressure move that is often untrue. What we can say honestly is that the claim is consistent with documented tradecraft, where the Vercel claim was flatly contradicted by it. Consistent-with is a real signal and it is not proof. Both halves of that sentence matter.
The part nobody is talking about: the platform has no name
EY calls it "a third-party information technology service management platform." That is the entire public description.
Think about what that does to every other organization on earth. If you run the same ITSM platform, you are in the blast radius of the same compromise and you cannot know it, because the one fact you need has not been published. You cannot check your logs for a window you can't scope to a product you can't name.
This is the recurring failure in third-party breach disclosure, and it is worse here than usual because of who the victim is. Ernst & Young is one of the Big Four. Their business includes auditing other organizations' security and controls. A firm in the business of assessing third-party risk got hit through its own third party, and the disclosure withholds the single detail that would let anyone else assess theirs.
We are not going to guess the platform's name. Guessing would name an innocent vendor on the strength of a hunch, which is the same error as attribution-by-claim wearing a different hat.
The timeline is the other story
March 28: intrusion begins.
April 12: intrusion ends.
April 23: EY detects it — eleven days after the attacker left.
Early July: public disclosure.
July 27: ShinyHunters posts the extortion deadline.
Roughly three months from detection to disclosure, and the extortion clock is now the thing forcing the pace. Whatever the internal reasons — and there are usually real ones, legal and forensic — the practical result is that clients whose tax data was in those tickets spent a quarter not knowing.
The data is the worst kind for the victim population: tax filings mean names, Social Security numbers, income, dependents, addresses. That is not a password you rotate. It is the permanent identity substrate, and it is exactly the raw material for the credential-stuffing and sextortion economy that ShinyHunters-branded leaks have been feeding — which we wrote about earlier today in the context of the $2,000 sextortion wave riding on their previous dumps.
What to do
If you are an EY tax client: take the 24 months of Experian monitoring, but understand it is detection, not prevention. Freeze your credit at all three bureaus — that is the control that actually blocks new-account fraud, it is free, and it does not expire in 24 months. Get an IRS Identity Protection PIN before next filing season; stolen tax data's highest-value use is filing a fraudulent return in your name.
If you run any third-party ITSM platform: you cannot check for this specific compromise, so check the general case. Audit which third-party platforms hold your ticket attachments, and go look at what is actually in them. Support tickets are where sensitive documents go to be forgotten — people attach the tax return, the config with credentials in it, the customer list, because a ticket feels ephemeral. It is not. It is a document store with weaker controls than your document store.
Rotate what a support platform can reach. ShinyHunters claims the credentials led onward to Jira, GitHub, and Azure. Whether or not that specific claim holds, it describes the real risk: ITSM platforms accumulate integration tokens with standing access to everything they connect to. Enumerate those tokens. Most organizations have never counted them.
Watch the July 31 deadline. If data lands, it lands this week.
No indicators, and we will say so
There are no published IOCs for this. No infrastructure, no hashes, no domains — the platform is unnamed and neither party has released technical detail. So there is nothing for us to put in the feed, and we are not going to manufacture something to look useful.
What we can offer is the framework, applied honestly in both directions on the same day: a claim we rejected this morning, and a claim we find credible this afternoon, judged by the same standard. If we only ever used the skepticism to knock claims down, it would be a pose rather than a method.
We are 95 percent confident the platform gets named eventually — through litigation, a regulatory filing, or another victim disclosing more fully. The remaining five percent is that it stays buried under NDA, which happens more often than the industry admits and is the reason third-party risk stays unmeasurable for everyone downstream.
Free IP, domain, hash, and malicious-package blocklists at analytics.dugganusa.com.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.




Comments