ShinyHunters Claims Data Theft From EY, Stealing Company Data
Key Takeaways The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young (EY). The breach, which EY first detected on April 23, 2026, involved unauthorized...
Key Takeaways
- The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young (EY).
- The breach, which EY first detected on April 23, 2026, involved unauthorized access to a third-party IT service management platform.
- Sensitive client tax documents, including names, Social Security numbers, and financial details, were exposed.
- ShinyHunters has issued an ultimatum, threatening to leak all stolen data by July 31, 2026, if EY does not negotiate.
- EY is offering two years of free credit monitoring and identity restoration services to affected individuals.
The notorious cyber extortion collective, ShinyHunters, has publicly asserted responsibility for a data breach impacting global professional services firm Ernst & Young (EY). The group alleges it successfully exfiltrated employee credentials and sensitive files by compromising a third-party IT support platform within EY’s supply chain.
Table Of Content
A “final warning” posted on ShinyHunters’ dark web leak site sets a deadline of July 31, 2026. The threat actor group states it will release all purloined data and documents if EY fails to engage in negotiations before this date.
EY initially disclosed the security incident earlier this month. The firm reported detecting unusual activity on April 23, 2026, within an IT service management platform. This platform is utilized by internal staff to facilitate client work related to tax services.
The subsequent investigation by EY revealed that an unauthorized third party maintained access to the platform between March 28 and April 12, 2026. During this approximately two-week period, the intruders downloaded documents associated with numerous EY clients.
Compromised support tickets frequently contained attached client tax documents. This exposure included sensitive personal information such as names, addresses, Social Security numbers, financial account numbers, credit and debit card details, and other data essential for preparing tax filings.
EY filed breach notification letters with regulatory bodies, including the Attorneys General of California and Texas. These filings confirmed a minimum of 1,366 affected residents across various U.S. states, though given EY’s extensive global client base, the actual number is likely substantially higher.
EY has stated it has no current knowledge of any misuse of the stolen data and does not believe any specific client was individually targeted. To mitigate potential harm, the firm is providing two years of complimentary credit monitoring and identity restoration services to individuals impacted by the breach.
ShinyHunters’ Extortion Claim
Prior to this week, no threat actor had claimed responsibility for the attack, and EY had not publicly disclosed the method of intrusion into the third-party platform. This changed when ShinyHunters added EY to its leak site, alongside other new victims such as RingCentral and Brinks Home. The group explicitly claimed the breach originated from a supply-chain attack that provided credentials to EY’s internal systems.
The group’s leak-site notice, which was updated on July 27, 2026, issues a stark warning: “This is a final warning to reach out by 31 July 2026 before we leak along with several ongoing (digital) problems.” This ultimatum is directed at EY should the firm fail to respond to ShinyHunters’ attempts at contact.
This tactic aligns with ShinyHunters’ established operational blueprint, observed in recent campaigns targeting Instructure, Charter Communications, and McGraw Hill. In these instances, the group leveraged vulnerabilities in SaaS platforms, compromised SSO credentials, and employed vishing attacks to exfiltrate significant volumes of data before demanding ransom payments.
ShinyHunters has emerged as one of the most active extortion operations in 2026. The group operates a dedicated leak site and frequently exploits third-party and supply-chain weaknesses, often opting for these vectors over direct network intrusions.
Recent victims linked to the group include Instructure’s Canvas LMS, an incident that potentially affected up to 275 million individuals, and Charter Communications, where an alleged 40 million records were taken via a compromised Microsoft Entra account and Salesforce instance.
Security researchers have noted a frequent overlap between ShinyHunters and the “Scattered Lapsus$ Hunters” collective. This associated group has also claimed attacks on entities like Abbott Laboratories, employing similar techniques such as vishing and exploitation of SaaS platforms.
As of the time of this report, EY has not confirmed the specific claims made by ShinyHunters, nor has it publicly responded to the July 31 deadline. No stolen data has yet appeared on underground forums.
What You Should Do
- If you are an EY client, particularly one whose tax documents are handled by EY, monitor your financial accounts and credit reports for any suspicious activity.
- Take advantage of the two years of free credit monitoring and identity restoration services offered by EY if you are an affected individual.
- Be vigilant against phishing attempts that may leverage information exposed in this breach.
- Consider implementing multi-factor authentication (MFA) on all your online accounts, especially those containing sensitive personal or financial information.
- Review privacy settings and security practices for any third-party services you use that integrate with critical business platforms.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.