ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.

Listen to this article

0:00

Press play to start listening

ShinyHunters has claimed responsibility for a data breach at professional services firm Ernst & Young (EY), threatening to publish stolen files unless the company contacts the group by July 31, 2026.

The extortion group added EY to its dark web leak site on July 27 with the message, “Yes it was us. Now come talk to us.” It said the company had until the end of July to respond before the data was released and further unspecified disruption followed.

EY Detected the Breach in April

EY had already confirmed a breach earlier in July, but it did not identify the attacker. According to a notification (PDF) filed with the California Attorney General, the company detected unusual activity on April 23 within a third-party IT service management platform used by its personnel to support tax-related client work.

An investigation found that an unauthorized party accessed the platform between March 28 and April 12, 2026, and downloaded documents belonging to several EY clients. Support tickets submitted through the system sometimes included files containing client tax information.

Furthermore, documents taken from the platform contained personal and financial information used in tax filings. Regulatory disclosures indicate that the exposed information may include names, addresses, Social Security numbers, financial account codes, account numbers, payment card details and investment information.

EY said it secured its systems, removed the unauthorized access and notified federal law enforcement. The firm also began offering affected clients 24 months of credit monitoring, identity monitoring and identity restoration services through Experian.

The total number of people affected has not been disclosed.

Screenshot from the dark web leak site of the ShinyHunters group (Image credit: Hackread.com)

ShinyHunters Claims Wider Access

Following its dark web post, ShinyHunters reportedly said it obtained EY credentials through an unidentified supply-chain compromise. The group claimed those credentials provided access to the company’s Jira, GitHub and Microsoft Azure environments.

Those additional claims remain unverified and ShinyHunters has not named the alleged third-party supplier, explained how the credentials were obtained or described the files it says it stole. EY has also not confirmed that the group was responsible or that Jira, GitHub and Azure systems were accessed.

Nevertheless, ShinyHunters has carried out several data-theft and extortion campaigns during 2026, often publishing victim names and deadlines to pressure organizations into negotiations. Its listing of EY follows the same pattern.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts