Dormant High impact Data breach Checked 1w ago

ShinyHunters claims EY breach, threatens tax data leak

The extortion group ShinyHunters says it stole data from Ernst & Young through a support ticket platform used for tax-related client work. The group claims it obtained system credentials through a third-party IT vendor. EY has notified affected clients and regulators in at least four US states that a hacker accessed financial and tax data for about two weeks in early 2026. EY has not confirmed ShinyHunters' role. The group's July 31 deadline passed without a confirmed release of the stolen files, and no new EY-specific activity has been reported.

Started
Mar 28, 2026
Latest activity
Jul 31, 2026
Attributed to
ShinyHuntersSuspected
Where
United States
Sectors
Finance
Scale
one global professional services firm (Ernst & Young)

Current status

As of August 31, 2026, no new EY data release, demand, attribution update, or other confirmed activity has been reported since August 15.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

EY has confirmed the breach but has not confirmed that ShinyHunters was responsible or that the group's claim refers to the same incident.

Impact

Attackers reportedly accessed an IT service management platform EY staff use to support tax-related client work, first detected around April 23, 2026. EY has confirmed to clients that a hacker accessed financial and tax data for roughly two weeks in early 2026, and has notified regulators in at least four US states. ShinyHunters claims it obtained employee credentials and client tax records and threatened to publish them if EY did not negotiate. EY also faces at least one proposed class action lawsuit over the breach.

What to do

EY clients who used its tax support platform should watch for a direct notification from EY, follow any guidance from their state attorney general if notified, and treat any unexpected tax-related contact with extra caution.

Timeline

  1. Aug 15, 2026

    The Next Web reported that EY had not publicly linked ShinyHunters' listing to the breach it disclosed, leaving the group's role unconfirmed.

    Dormantthenextweb.com
  2. Jul 31, 2026

    ShinyHunters' stated deadline for EY to respond passed with no confirmed publication of the stolen data yet reported.

    Activeransomware.live
  3. Jul 29, 2026

    Security press reported the extortion deadline still stood at July 31 with no confirmed data publication yet.

    Activesecurityweek.com
  4. Jul 27, 2026

    ShinyHunters told reporters it obtained EY credentials through a supply-chain attack on the third-party platform and reiterated its leak threat.

    Activebleepingcomputer.com
  5. Jul 27, 2026

    ShinyHunters claimed the breach and demanded contact before July 31 under threat of publishing the data.

    Activebleepingcomputer.com
  6. Jul 27, 2026

    ShinyHunters posted a further public message on its leak site pressing EY to negotiate before the deadline.

    Activeransomware.live
  7. Jul 13, 2026

    EY told affected people that access had been stopped, its systems were secure, and monitoring continued.

    oag.ca.gov
  8. Jul 8, 2026

    ShinyHunters told BleepingComputer it obtained credentials for EY systems through a supply-chain attack on a third-party platform.

    Activebleepingcomputer.com
  9. Jul 1, 2026

    ShinyHunters added EY to its dark web leak site and threatened to publish stolen tax records unless EY began negotiations by July 31.

    Activesecurityaffairs.com
  10. Jul 1, 2026

    ShinyHunters added EY to its dark web leak site and threatened to publish stolen tax records unless EY made contact by July 31.

    Activesecurityaffairs.com
  11. Apr 23, 2026

    EY detected unusual activity, started its response, and brought in an outside security firm.

    oag.ca.gov
  12. Apr 23, 2026

    EY detected anomalous activity within an IT service management platform used by staff to support tax-related client work.

    Emergingcybersecuritynews.com
  13. Apr 12, 2026

    The period of unauthorized access identified by EY ended.

    Containedoag.ca.gov
  14. Mar 28, 2026

    An unauthorized party began accessing EY's third-party support platform and downloading client documents.

    Activeoag.ca.gov

Sources

Related reports