ShinyHunters claims EY breach, threatens tax data leak
The extortion group ShinyHunters says it stole data from Ernst & Young through a support ticket platform used for tax-related client work. The group claims it obtained system credentials through a third-party IT vendor. EY has notified affected clients and regulators in at least four US states that a hacker accessed financial and tax data for about two weeks in early 2026. EY has not confirmed ShinyHunters' role. The group's July 31 deadline passed without a confirmed release of the stolen files, and no new EY-specific activity has been reported.
- Started
- Mar 28, 2026
- Latest activity
- Jul 31, 2026
- Attributed to
- ShinyHuntersSuspected
- Where
- United States
- Sectors
- Finance
- Scale
- one global professional services firm (Ernst & Young)
Current status
As of August 31, 2026, no new EY data release, demand, attribution update, or other confirmed activity has been reported since August 15.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
EY has confirmed the breach but has not confirmed that ShinyHunters was responsible or that the group's claim refers to the same incident.
Impact
Attackers reportedly accessed an IT service management platform EY staff use to support tax-related client work, first detected around April 23, 2026. EY has confirmed to clients that a hacker accessed financial and tax data for roughly two weeks in early 2026, and has notified regulators in at least four US states. ShinyHunters claims it obtained employee credentials and client tax records and threatened to publish them if EY did not negotiate. EY also faces at least one proposed class action lawsuit over the breach.
What to do
EY clients who used its tax support platform should watch for a direct notification from EY, follow any guidance from their state attorney general if notified, and treat any unexpected tax-related contact with extra caution.
Timeline
-
Aug 15, 2026
The Next Web reported that EY had not publicly linked ShinyHunters' listing to the breach it disclosed, leaving the group's role unconfirmed.
Dormantthenextweb.com -
Jul 31, 2026
ShinyHunters' stated deadline for EY to respond passed with no confirmed publication of the stolen data yet reported.
Activeransomware.live -
Jul 29, 2026
Security press reported the extortion deadline still stood at July 31 with no confirmed data publication yet.
Activesecurityweek.com -
Jul 27, 2026
ShinyHunters told reporters it obtained EY credentials through a supply-chain attack on the third-party platform and reiterated its leak threat.
Activebleepingcomputer.com -
Jul 27, 2026
ShinyHunters claimed the breach and demanded contact before July 31 under threat of publishing the data.
Activebleepingcomputer.com -
Jul 27, 2026
ShinyHunters posted a further public message on its leak site pressing EY to negotiate before the deadline.
Activeransomware.live -
Jul 13, 2026
EY told affected people that access had been stopped, its systems were secure, and monitoring continued.
oag.ca.gov -
Jul 8, 2026
ShinyHunters told BleepingComputer it obtained credentials for EY systems through a supply-chain attack on a third-party platform.
Activebleepingcomputer.com -
Jul 1, 2026
ShinyHunters added EY to its dark web leak site and threatened to publish stolen tax records unless EY began negotiations by July 31.
Activesecurityaffairs.com -
Jul 1, 2026
ShinyHunters added EY to its dark web leak site and threatened to publish stolen tax records unless EY made contact by July 31.
Activesecurityaffairs.com -
Apr 23, 2026
EY detected unusual activity, started its response, and brought in an outside security firm.
oag.ca.gov -
Apr 23, 2026
EY detected anomalous activity within an IT service management platform used by staff to support tax-related client work.
Emergingcybersecuritynews.com -
Apr 12, 2026
-
Mar 28, 2026
An unauthorized party began accessing EY's third-party support platform and downloading client documents.
Activeoag.ca.gov
Sources
- Ernst & Young data breach claimed by ShinyHunters extortion gang BleepingComputer Jul 8, 2026
- EY data breach by ShinyHunters attackers Cyber Security News Jul 9, 2026
- ShinyHunters threatens to leak EY tax data SecurityAffairs Jul 1, 2026
- ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data GBHackers Jul 27, 2026
- Shinyhunters ransomware claims Ernst & Young ransomware.live Jul 27, 2026
- ShinyHunters Claims Ernst & Young Hack SecurityWeek Jul 29, 2026
- Ernst & Young breach exposes client tax data ZDNET Jul 21, 2026
- Ernst & Young discloses data breach after support system hack BleepingComputer Jul 17, 2026
- EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified Tech Times Jul 19, 2026
- Hacked! Ernst & Young informs clients of third-party data breach Cyber Daily Jul 21, 2026
- EY hit with proposed class action over data breach CFO Dive Jul 21, 2026 unverified
- Major professional services firm faces extortion threat after ShinyHunters breach Computing Jul 29, 2026
- Submitted Breach Notification Sample: Ernst & Young LLP California Office of the Attorney General Jul 15, 2026
- Notice of Data Breach Ernst & Young via California Office of the Attorney General Jul 13, 2026
- A phone company just lost 1.6 million records to a phone call The Next Web Aug 15, 2026
Related reports
- Shinyhunters ransomware claims Questel SAS Aug 1, 2026
- ShinyHunters claims data theft from Lumenis Aug 1, 2026
- Shinyhunters ransomware claims Alcon Inc. Aug 1, 2026
- Origin Energy breach exposes customer information Jul 28, 2026
- Shinyhunters ransomware claims RingCentral, Inc. Jul 27, 2026
- ShinyHunters claims attack on Ernst & Young Jul 27, 2026
- OnTrac customer data breach exposes personal info Jul 27, 2026
- EY breach threatens to expose client tax data Jul 27, 2026
- Origin Energy customer data stolen in Australia Jul 24, 2026
- Origin Energy data breach exposes customer info Jul 24, 2026
- Chick-fil-A One data exposed in login attack Jul 23, 2026
- Chick-fil-A accounts hacked via stolen passwords Jul 22, 2026