Dormant Medium impact Data breach Checked 1d ago

EY tax support breach exposes client financial data

An intruder accessed a third-party support platform used by EY's US tax practice from March 28 to April 12 and downloaded client documents containing personal and financial data. EY said the access was stopped. ShinyHunters later claimed the theft and threatened to publish the files, but its July 31 deadline passed without a confirmed public leak. EY has not confirmed the group's claim. A proposed class action lawsuit was filed against EY on July 28 over the breach.

Started
Mar 28, 2026
Latest activity
Jul 28, 2026
Attributed to
ShinyHuntersSuspected
Where
United States
Sectors
Finance
Scale
EY and an undisclosed number of clients

Current status

No credible post-August 5 report has documented an EY leak or official closure; separate reports dated August 28 and September 9 show ShinyHunters remained active against other victims.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

ShinyHunters claimed responsibility, but EY has not confirmed the link and no independent evidence has proved it.

Impact

The intruder downloaded support-ticket documents containing personal information and financial data used in tax filings. EY said on July 13 that it was not aware of misuse or further exposure. A proposed class action filed July 28 alleges EY failed to protect this data; the claims are unproven and there is nothing for affected people to file yet.

What to do

People who received an EY notice should use the offered monitoring, review financial accounts, and consider requesting an IRS identity protection PIN.

Timeline

  1. Sep 11, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Sep 9, 2026

    GovInfoSecurity reported that ShinyHunters continued claiming attacks against other organizations, including Florida's DMV. No new EY activity or EY data leak was reported.

    govinfosecurity.com
  3. Sep 8, 2026

    BleepingComputer reported that ShinyHunters claimed a separate breach of Florida's DAVID DMV database. No connection to the EY incident was reported.

    bleepingcomputer.com
  4. Aug 28, 2026

    BleepingComputer reported that McKesson disclosed a separate incident after ShinyHunters claimed to have stolen patient data. No connection to the EY incident was reported.

    bleepingcomputer.com
  5. Aug 5, 2026

    A review found no public leak after ShinyHunters' July 31 deadline, while EY had not confirmed the group's claim or issued a closure notice.

    Containedcloudskope.com
  6. Jul 28, 2026

    EY was hit with a proposed class action lawsuit alleging it failed to protect client tax and financial data exposed in the breach.

    Containedcfodive.com
  7. Jul 27, 2026

    ShinyHunters claimed responsibility and threatened to publish the stolen files unless EY responded by July 31.

    ransomware.live
  8. Jul 13, 2026

    EY notified affected people, offered 24 months of identity monitoring, and said its systems were secure.

    oag.ca.gov
  9. Apr 23, 2026

    EY detected unusual activity and started its response, investigation, and recovery work.

    oag.ca.gov
  10. Apr 12, 2026

    EY's investigation found that the unauthorized access ended after documents belonging to several clients were downloaded.

    Containedoag.ca.gov
  11. Mar 28, 2026

    An unauthorized party began accessing the third-party support platform used by EY's tax practice.

    Activeoag.ca.gov

Sources

Related reports