ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31.
The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to publish the stolen data unless negotiations begin by July 31.
Earlier this month, EY notified several U.S. state Attorneys General that attackers had gained unauthorized access to a third-party service management platform used to support tax-related operations. According to the company’s filings, the intrusion occurred between March 28 and April 12, during which threat actors downloaded documents attached to customer support tickets.
“EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.” reads the data breach notification. ” “EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts. EY has worked with an independent cybersecurity firm to investigate the incident and confirm that the unauthorized access has been stopped, and our systems are now secure. Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorized third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients.”
The exposed information includes highly sensitive personal and financial data used for tax preparation, such as names, addresses, Social Security numbers, bank account details, payment card information, and other tax-related records. EY said the incident affected data stored within the external support platform rather than its core internal systems.
While the company has not disclosed how many individuals were impacted or publicly attributed the attack, it is offering affected customers 24 months of complimentary credit monitoring, identity monitoring, and identity restoration services. EY has also remained silent on whether it has been in contact with the attackers.
The claim by ShinyHunters adds to a growing list of high-profile victims attributed to the group. In recent months, the extortion gang has claimed responsibility for breaches affecting organizations such as DentaQuest, 7-Eleven, Medtronic, and campaigns targeting Oracle PeopleSoft and Salesforce environments.
The group is known for stealing large volumes of sensitive data and using the threat of public disclosure to pressure victims into paying a ransom.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, ShinyHunters)
Click Here For The Original Source.
