ShinyHunters claims E&Y breach via supply-chain attack


Wednesday Free Edition - July 29, 2026

Threat of the Week: ShinyHunters Claims Ernst & Young Breach

The ShinyHunters extortion gang has claimed responsibility for a data breach at professional services giant Ernst & Young, alleging it obtained credentials for some of the firm's systems through a supply-chain attack. According to Bleeping Computer, the group says the intrusion was made possible not by directly targeting E&Y's own infrastructure, but by compromising a third-party vendor in its supply chain — a reminder that even the largest professional services firms remain exposed through the partners and platforms they rely on.

ShinyHunters has a well-documented history of large-scale data theft and extortion operations. Their involvement here is significant because supply-chain intrusions that yield valid credentials can be exceptionally difficult to detect and contain in a timely manner. Organizations that share privileged access with third-party vendors should treat this incident as a direct signal to audit those trust relationships now.

  • Actor: ShinyHunters extortion gang
  • Method: Supply-chain attack leading to credential access
  • Target: Ernst & Young
  • Status: Breach claimed; details under investigation

Deep Dive: Shadow AI Agents Are Multiplying — And Security Teams Can't See Them

Enterprise environments are quietly filling up with AI agents that IT and security teams never approved, inventoried, or assessed. These so-called shadow AI agents — spun up by individual employees or business units through consumer and SaaS platforms — are accumulating permissions, connecting to corporate data, and taking autonomous actions entirely outside formal governance processes. Bleeping Computer reports that security firm Nudge Security has outlined a framework for discovering, assessing, and governing these agents before they become a serious liability.

The core risk is compounding: an unmanaged AI agent may hold OAuth tokens or API keys with broad scopes, act on behalf of users without human review, and create data flows that bypass existing DLP controls. Unlike traditional shadow IT — a rogue SaaS subscription, say — an autonomous agent can act, not just store. The discovery challenge is also harder, because agents are often embedded inside platforms the organization already sanctions.

Nudge Security's recommended approach, as reported, centers on three pillars:

  • Discovery: Continuously scan for AI integrations and OAuth grants across your SaaS estate, not just at point-in-time audits.
  • Assessment: Evaluate the permissions each agent holds, the data it can access, and whether it has the ability to take external actions.
  • Governance: Establish a formal AI agent registration process so new agents require review before being granted production access.

Security leaders should note that the window for proactive control is narrowing. As more productivity platforms build native agentic capabilities, the default path of least resistance for employees will increasingly be to deploy agents without any security touchpoint at all.


Hack of the Week: Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack

The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary Fairlife during a ransomware attack that occurred earlier this month, according to Bleeping Computer. The confirmation follows the company's initial disclosure of the incident and underscores a now-standard ransomware playbook: encrypt systems, exfiltrate data, and use the stolen information as additional leverage in extortion demands.

Fairlife is a significant subsidiary — best known for its filtered milk and protein shake products — and operates its own supply chain and customer data infrastructure. The confirmation of data theft, rather than mere operational disruption, raises the stakes considerably: affected data could include employee records, customer information, or proprietary business data, though the specific categories have not been detailed in available reporting.

This incident is a useful case study in why ransomware response plans must treat data exfiltration as a baseline assumption, not an exception. Organizations should architect their environments so that even if an attacker gains a foothold, lateral movement toward sensitive data repositories is constrained and detectable.


Tool Spotlight: The Dysphoria Botnet — 200,000 Devices and Counting

A newly identified botnet called Dysphoria has compromised approximately 200,000 devices worldwide and is actively being used for distributed denial-of-service (DDoS) attacks and traffic relay operations, according to Bleeping Computer. The scale of the Dysphoria network places it firmly in the tier of botnets capable of launching volumetrically significant attacks against enterprise and critical infrastructure targets.

The dual-use nature of Dysphoria — both DDoS capability and traffic relay — is worth noting. Traffic relay infrastructure is frequently used to anonymize the origin of other attacks, making it harder for defenders and investigators to attribute malicious activity. A botnet that serves both functions simultaneously can be rented or leveraged for a broad range of criminal operations beyond pure disruption.

Defenders and network operators should be aware of the following:

  • Devices in the botnet are being used as unwitting relay nodes, meaning your own infrastructure could be a participant without any visible compromise indicator at the application layer.
  • DDoS mitigation postures should account for geographically distributed, device-diverse botnets that do not conform to classic IP-block-based defenses.
  • Organizations operating large fleets of internet-connected devices — particularly routers, cameras, and similar endpoints — should verify firmware currency and access control hygiene.

Breach Board: Fake Crypto Wallet App Drains $1.8M in Bitcoin via Apple App Store

Three individuals have filed a lawsuit against Apple, alleging that approximately $1.8 million in Bitcoin was stolen after they downloaded a fraudulent Sparrow Wallet application from the official App Store, according to Bleeping Computer. The plaintiffs allege that the counterfeit application impersonated the legitimate Sparrow Wallet — a well-known Bitcoin wallet — and was able to pass through Apple's app review process and appear in search results.

The lawsuit puts renewed pressure on Apple's longstanding claim that its closed App Store model provides meaningful security guarantees to users. For consumers who rely on the App Store as a trusted distribution channel — particularly for high-stakes applications like cryptocurrency wallets — this incident is a stark reminder that platform approval is not a guarantee of legitimacy.

Practical guidance for users managing cryptocurrency assets:

  • Always navigate directly to the official project website to find the verified download link for any wallet application — do not rely solely on App Store search results.
  • Verify the developer name, publisher account history, and review count before downloading any financial application.
  • For significant holdings, consider hardware wallet solutions that do not depend on software applications for key storage.

Found this useful? Forward Cyber Threat Weekly to a colleague who needs to stay sharp. Have a tip, correction, or story lead? Reply directly to this email — we read every note. Not yet a subscriber? Sign up for free at our website to get every issue delivered every Wednesday.

Subscribe to Cyber Threats Weekly