Ernst & Young has become the latest major firm named by the ShinyHunters extortion gang. The group claims it carried out the recently disclosed EY data breach after gaining company credentials through a supply-chain attack.

EY confirmed earlier this month that attackers had compromised a third-party support ticket platform used by its IT teams. The stolen tickets may have included documents containing client tax information.

However, EY has not confirmed ShinyHunters’ involvement. It also has not publicly named the affected platform or disclosed the number of people affected.

Attackers accessed the system for weeks

EY detected unusual activity on 23 April and launched an investigation. The company determined that an unauthorised party had accessed the third-party platform between 28 March and 12 April.

During that period, the attacker downloaded multiple documents from the system.

The platform helps EY IT staff provide technical support to teams that perform tax-related work for clients. As a result, support tickets can contain files with sensitive personal and financial information used in tax filings.

EY has not confirmed the exact categories of information exposed. It has also not said how many clients or individuals may have had data included in the stolen records.

ShinyHunters alleges a supply-chain attack

ShinyHunters added Ernst & Young to its data leak site on 27 July. The gang threatened to release the allegedly stolen data unless the company contacts it by 31 July 2026.

The group claims it obtained EY credentials by compromising a third-party provider. It alleges that those credentials gave it access to EY’s Jira, GitHub and Azure environments.

According to the gang, the exposed material includes the information EY has already acknowledged, as well as additional data. However, it did not identify the allegedly breached third party or provide evidence to support its claims.

Therefore, the full scope of the EY data breach remains unclear.

EY has not verified the extortion claim

EY has not confirmed that ShinyHunters was behind the attack. The company has also not publicly said whether it received an extortion demand.

Following the incident, EY said it secured its systems and removed the unauthorised access. The firm also notified federal law enforcement.

Meanwhile, EY is offering affected clients 24 months of identity monitoring and restoration services through Experian.

The case highlights the risk that third-party support systems can create for major organisations. Even when attackers do not directly breach a company’s core network, a compromised supplier platform can still expose highly sensitive client information.


0 responses to “EY Data Breach Claimed by ShinyHunters Gang”