Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShinyHunters Takes Responsibility for EY Data Breach

ShinyHunters Takes Responsibility for EY Data Breach

Posted on July 27, 2026 By CWS

The infamous hacker group ShinyHunters has declared responsibility for a recent data breach at Ernst & Young (EY). The cybercriminals claim to have obtained employee credentials and confidential files by exploiting vulnerabilities in a third-party IT support platform.

Details of the Breach

ShinyHunters announced their involvement on a dark web site, issuing a ‘final warning’ to EY with a deadline of July 31, 2026. They threaten to expose the stolen data unless EY engages in negotiations. The breach became public knowledge earlier this month after EY detected unusual activity on April 23, 2026, within a platform used internally for tax-related client services.

Investigations revealed that unauthorized access to the platform occurred between March 28 and April 12, 2026. During this period, documents linked to numerous clients were downloaded, potentially exposing sensitive information such as names, addresses, Social Security numbers, and financial details.

Impact on Clients

EY has filed notification letters with regulatory bodies, including the Attorneys General in California and Texas, confirming that at least 1,366 residents across multiple states were affected. However, given EY’s global clientele, the true number of impacted individuals is likely higher.

Despite the breach, EY reports no evidence of the stolen data being misused and does not believe any client was specifically targeted. The firm is offering two years of complimentary credit monitoring and identity restoration services to those affected.

ShinyHunters’ Methodology

ShinyHunters’ declaration marks the first time the group has claimed this attack, previously undisclosed by EY regarding the breach method. The group added EY to its list of victims, alongside other companies like RingCentral and Brinks Home, suggesting a supply-chain attack facilitated access to EY’s systems.

This tactic is consistent with ShinyHunters’ approach, seen in previous attacks on entities such as Instructure and Charter Communications, where they exploited SaaS platforms and credentials to extract large amounts of data before demanding ransoms.

As of now, EY has not publicly confirmed ShinyHunters’ claims or addressed the impending deadline. No data from the breach has surfaced on illicit platforms, but security experts continue to monitor the situation closely.

Cyber Security News Tags:client data, credit monitoring, cyber threat, Cybersecurity, data breach, data protection, digital security, Extortion, EY, hacker group, identity theft, Information Security, IT security, ShinyHunters, supply chain attack

Post navigation

Previous Post: Uncovering Mobile App Vulnerabilities with Lookout MSEC
Next Post: Dysphoria Botnet Adopts Blockchain for Enhanced Security

Related Posts

Apache Tomcat Vulnerabilities Let Attackers Trigger Dos Attack Apache Tomcat Vulnerabilities Let Attackers Trigger Dos Attack Cyber Security News
Velvet Ant’s Long-Term Network Intrusion Uncovered Velvet Ant’s Long-Term Network Intrusion Uncovered Cyber Security News
Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287 Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287 Cyber Security News
Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Cyber Security News
Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely Critical Salesforce Tableau Vulnerabilities Let Attackers Execute Code Remotely Cyber Security News
Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign Operation ForumTrol Known for Exploiting Chrome 0-Day Attacking Users With New Phishing Campaign Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub Implements Cooldown to Thwart Malicious Packages
  • Cyber Threats Exploit Public Wi-Fi to Access Corporate Accounts
  • Dysphoria Botnet Adopts Blockchain for Enhanced Security
  • ShinyHunters Takes Responsibility for EY Data Breach
  • Uncovering Mobile App Vulnerabilities with Lookout MSEC

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub Implements Cooldown to Thwart Malicious Packages
  • Cyber Threats Exploit Public Wi-Fi to Access Corporate Accounts
  • Dysphoria Botnet Adopts Blockchain for Enhanced Security
  • ShinyHunters Takes Responsibility for EY Data Breach
  • Uncovering Mobile App Vulnerabilities with Lookout MSEC

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark