ShinyHunters Claims Responsibility for EY Data Breach

The cybercriminal group ShinyHunters has publicly claimed responsibility for the recent data breach at Ernst & Young (EY), alleging they obtained employee credentials and sensitive files through a supply-chain attack on a third-party IT support platform. The group has issued a “final warning” to EY, threatening to release the stolen data if the firm does not engage in negotiations by July 31, 2026.

EY initially disclosed the breach earlier this month after detecting unusual activity on April 23, 2026, within an IT service management platform used by its staff for tax-related client support. Investigations revealed that unauthorized access occurred between March 28 and April 12, 2026, during which documents related to numerous clients were downloaded. These documents contained sensitive information, including names, addresses, Social Security numbers, financial account details, and other data pertinent to tax filings.

The firm has filed breach notification letters with regulators, including the Attorneys General of California and Texas, confirming that at least 1,366 residents across multiple states were affected. Given EY’s extensive global client base, the actual number of impacted individuals is likely higher. EY has stated that there is no evidence of misuse of the stolen data and does not believe any specific client was individually targeted. The firm is offering two years of free credit monitoring and identity restoration services to those affected.

ShinyHunters’ Extortion Tactics

ShinyHunters listed EY on its dark web leak site alongside other victims, such as RingCentral and Brinks Home, claiming the intrusion resulted from a supply-chain attack that provided access to EY’s internal systems. The group’s notice, updated on July 27, 2026, warns of potential data leaks and “ongoing (digital) problems” if EY fails to respond by the specified deadline.

This approach aligns with ShinyHunters’ established methods observed in recent attacks on companies like Instructure, Charter Communications, and McGraw Hill. The group often exploits vulnerabilities in Software as a Service (SaaS) platforms, Single Sign-On (SSO) credentials, and employs vishing attacks to exfiltrate large volumes of data before demanding ransom payments.

ShinyHunters has become one of the most active extortion groups in 2026, frequently targeting third-party and supply-chain weaknesses rather than direct network intrusions. Notable recent victims include Instructure’s Canvas Learning Management System, affecting up to 275 million individuals, and Charter Communications, where 40 million records were allegedly obtained through compromised Microsoft Entra accounts and Salesforce instances.

As of now, EY has not publicly confirmed ShinyHunters’ specific claims or responded to the July 31 deadline. No stolen data has appeared on underground forums at this time.

This incident underscores the critical importance of securing third-party platforms and supply-chain components. Organizations must rigorously assess and monitor the security practices of their vendors and partners to prevent such breaches. The EY case serves as a stark reminder that even indirect vulnerabilities can lead to significant data exposures, emphasizing the need for comprehensive cybersecurity strategies that encompass all facets of an organization’s operations.