Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Defender for Endpoint Flaw Exposes Linux Servers
July 27, 2026
ShinyHunters Claims Data Theft From EY, Stealing Company Data
July 27, 2026
Critical vBulletin Bug CVE-2019-16759 Lets Attackers Remotely Execute Code
July 27, 2026
Home/CyberSecurity News/ShinyHunters Claims Data Theft From EY, Stealing Company Data
CyberSecurity News

ShinyHunters Claims Data Theft From EY, Stealing Company Data

Key Takeaways The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young (EY). The breach, which EY first detected on April 23, 2026, involved unauthorized...

Sarah simpson
Sarah simpson
July 27, 2026 4 Min Read
3 0

Key Takeaways

  • The ShinyHunters extortion group has claimed responsibility for a data breach at Ernst & Young (EY).
  • The breach, which EY first detected on April 23, 2026, involved unauthorized access to a third-party IT service management platform.
  • Sensitive client tax documents, including names, Social Security numbers, and financial details, were exposed.
  • ShinyHunters has issued an ultimatum, threatening to leak all stolen data by July 31, 2026, if EY does not negotiate.
  • EY is offering two years of free credit monitoring and identity restoration services to affected individuals.

The notorious cyber extortion collective, ShinyHunters, has publicly asserted responsibility for a data breach impacting global professional services firm Ernst & Young (EY). The group alleges it successfully exfiltrated employee credentials and sensitive files by compromising a third-party IT support platform within EY’s supply chain.

Table Of Content

  • Key Takeaways
  • ShinyHunters’ Extortion Claim
  • What You Should Do

A “final warning” posted on ShinyHunters’ dark web leak site sets a deadline of July 31, 2026. The threat actor group states it will release all purloined data and documents if EY fails to engage in negotiations before this date.

EY initially disclosed the security incident earlier this month. The firm reported detecting unusual activity on April 23, 2026, within an IT service management platform. This platform is utilized by internal staff to facilitate client work related to tax services.

The subsequent investigation by EY revealed that an unauthorized third party maintained access to the platform between March 28 and April 12, 2026. During this approximately two-week period, the intruders downloaded documents associated with numerous EY clients.

Compromised support tickets frequently contained attached client tax documents. This exposure included sensitive personal information such as names, addresses, Social Security numbers, financial account numbers, credit and debit card details, and other data essential for preparing tax filings.

EY filed breach notification letters with regulatory bodies, including the Attorneys General of California and Texas. These filings confirmed a minimum of 1,366 affected residents across various U.S. states, though given EY’s extensive global client base, the actual number is likely substantially higher.

EY has stated it has no current knowledge of any misuse of the stolen data and does not believe any specific client was individually targeted. To mitigate potential harm, the firm is providing two years of complimentary credit monitoring and identity restoration services to individuals impacted by the breach.

ShinyHunters’ Extortion Claim

Prior to this week, no threat actor had claimed responsibility for the attack, and EY had not publicly disclosed the method of intrusion into the third-party platform. This changed when ShinyHunters added EY to its leak site, alongside other new victims such as RingCentral and Brinks Home. The group explicitly claimed the breach originated from a supply-chain attack that provided credentials to EY’s internal systems.

The group’s leak-site notice, which was updated on July 27, 2026, issues a stark warning: “This is a final warning to reach out by 31 July 2026 before we leak along with several ongoing (digital) problems.” This ultimatum is directed at EY should the firm fail to respond to ShinyHunters’ attempts at contact.

This tactic aligns with ShinyHunters’ established operational blueprint, observed in recent campaigns targeting Instructure, Charter Communications, and McGraw Hill. In these instances, the group leveraged vulnerabilities in SaaS platforms, compromised SSO credentials, and employed vishing attacks to exfiltrate significant volumes of data before demanding ransom payments.

ShinyHunters has emerged as one of the most active extortion operations in 2026. The group operates a dedicated leak site and frequently exploits third-party and supply-chain weaknesses, often opting for these vectors over direct network intrusions.

Recent victims linked to the group include Instructure’s Canvas LMS, an incident that potentially affected up to 275 million individuals, and Charter Communications, where an alleged 40 million records were taken via a compromised Microsoft Entra account and Salesforce instance.

Security researchers have noted a frequent overlap between ShinyHunters and the “Scattered Lapsus$ Hunters” collective. This associated group has also claimed attacks on entities like Abbott Laboratories, employing similar techniques such as vishing and exploitation of SaaS platforms.

As of the time of this report, EY has not confirmed the specific claims made by ShinyHunters, nor has it publicly responded to the July 31 deadline. No stolen data has yet appeared on underground forums.

What You Should Do

  • If you are an EY client, particularly one whose tax documents are handled by EY, monitor your financial accounts and credit reports for any suspicious activity.
  • Take advantage of the two years of free credit monitoring and identity restoration services offered by EY if you are an affected individual.
  • Be vigilant against phishing attempts that may leverage information exposed in this breach.
  • Consider implementing multi-factor authentication (MFA) on all your online accounts, especially those containing sensitive personal or financial information.
  • Review privacy settings and security practices for any third-party services you use that integrate with critical business platforms.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical vBulletin Bug CVE-2019-16759 Lets Attackers Remotely Execute Code

Next Post

Critical Microsoft Defender for Endpoint Flaw Exposes Linux Servers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
NVIDIA Forms Open Secure AI Alliance for AI Agent Defenses
July 27, 2026
MedusaHVNC Malware Lets Attackers Remotely Control PCs
July 27, 2026
Vatican Click to Pray App API Flaw Exposes 700,000 User Records
July 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us