ShinyHunters Claims EY Breach, Threatens Data Leak by July 31
The extortion group says it stole employee credentials and client tax documents via a third-party platform compromise affecting at least 1,366 US residents.
ShinyHunters has claimed responsibility for the Ernst & Young data breach disclosed earlier this year, posting a July 31, 2026 deadline on their dark web leak site for negotiation before publishing stolen files.
Timeline of the Compromise
EY detected anomalous activity on April 23, 2026, in an IT service management platform used for tax-related client work. According to breach notifications filed with California and Texas Attorneys General, unauthorized access occurred between March 28 and April 12, 2026.
The professional services firm initially attributed the incident to a third-party IT support platform compromise. ShinyHunters alleges they obtained employee credentials and sensitive files through this supply-chain attack.
What Was Stolen
Stolen data includes client tax documents containing names, addresses, Social Security numbers, financial account numbers, and credit/debit card details. EY's regulatory filings confirm at least 1,366 affected US residents, though the actual scope may extend beyond those captured in state notifications.
On July 27, 2026, ShinyHunters updated their leak site with a direct threat: "This is a final warning to reach out by 31 July 2026 before we leak along with several ongoing (digital) problems."
ShinyHunters' 2026 Campaign
Active since 2019, ShinyHunters has established itself as one of the most prolific black-hat extortion groups targeting major companies in tech, finance, and retail. The group typically exploits SaaS platforms, supply-chain vulnerabilities, and vishing attacks to exfiltrate large volumes of data for ransom.
In 2026 alone, ShinyHunters has claimed responsibility for breaches at Instructure (Canvas LMS), Charter Communications, RingCentral, and Brinks Home. The EY claim fits this pattern of high-value targets with access to sensitive customer data.
Why This Matters
The breach carries significance given EY's position as one of the world's largest professional services firms. The company handles highly sensitive financial and tax data for a global clientele, making any compromise a significant identity theft and financial fraud risk.
The supply-chain nature of the attack underscores a persistent vulnerability for large enterprises: even robust internal security cannot fully protect against compromised third-party vendors. EY's initial disclosure noted the IT service management platform was used specifically for tax-related client work, suggesting the attackers targeted systems with direct access to the firm's most sensitive client records.
EY has not publicly responded to ShinyHunters' claim or the July 31 deadline. The firm's breach notifications indicate affected individuals were being contacted directly, but it remains unclear whether the company intends to negotiate with the extortion group or absorb the risk of a public data dump.