Cyber Security News

EY Data Breach Claimed by ShinyHunters Hacker Group

The notorious ShinyHunters extortion gang has publicly claimed responsibility for the Ernst & Young (EY) data breach, alleging it stole employee credentials and sensitive files through a supply-chain compromise of a third-party IT support platform.

The claim, posted on the group’s dark web leak site with a “final warning” deadline of July 31, 2026, threatens to release all stolen data and files if EY does not negotiate before the deadline.

EY first disclosed the incident earlier this month after detecting anomalous activity on April 23, 2026, within an IT service management platform used by internal staff to support tax-related client work.

Investigation revealed that an unauthorized third party had access to the platform from March 28 to April 12, 2026, downloading documents tied to numerous EY clients during that roughly two-week window.

The compromised support tickets often contained attached client tax documents, exposing names, addresses, Social Security numbers, financial account numbers, credit and debit card details, and other data used to prepare tax filings.

EY filed breach notification letters with regulators including the California and Texas Attorneys General, confirming a floor of at least 1,366 affected residents across multiple US states, though the firm’s global client base suggests the real number is significantly higher.

EY has stated it is unaware of any misuse of the stolen data and does not believe any specific client was individually targeted, and it is offering two years of free credit monitoring and identity restoration services to affected individuals.

ShinyHunters’ Extortion Claim

Until this week, no threat actor had claimed the attack, and EY had not disclosed how intruders breached the third-party platform. That changed when ShinyHunters listed EY on its leak site alongside other new victims, including RingCentral and Brinks Home, asserting the intrusion originated from a supply-chain attack that yielded credentials to EY’s internal systems.

EY Data Breach Claimed by ShinyHunters

The group’s leak-site notice, updated July 27, 2026, warns, “This is a final warning to reach out by 31 July 2026 before we leak along with several ongoing (digital) problems” if EY fails to respond to their contact attempts.

This tactic mirrors ShinyHunters’ established playbook seen in recent campaigns against Instructure, Charter Communications, and McGraw Hill, where the group exploited SaaS platforms, SSO credentials, and vishing attacks to exfiltrate large data volumes before demanding ransom.

ShinyHunters has emerged as one of 2026’s most prolific extortion operations, running a dedicated leak site and frequently exploiting third-party and supply-chain weaknesses rather than direct network intrusions.

Recent victims tied to the group include Instructure’s Canvas LMS, affecting up to 275 million individuals, and Charter Communications, where 40 million records were allegedly taken via a compromised Microsoft Entra account and Salesforce instance.

Security researchers note the group frequently overlaps with the “Scattered Lapsus$ Hunters” collective, which has also claimed attacks on firms like Abbott Laboratories using vishing and SaaS-platform exploitation techniques.

As of this writing, EY has not confirmed ShinyHunters’ specific claims or responded publicly to the July 31 deadline, and no stolen data has yet appeared on underground forums.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago