The infamous hacker group ShinyHunters has declared responsibility for a recent data breach at Ernst & Young (EY). The cybercriminals claim to have obtained employee credentials and confidential files by exploiting vulnerabilities in a third-party IT support platform.
Details of the Breach
ShinyHunters announced their involvement on a dark web site, issuing a ‘final warning’ to EY with a deadline of July 31, 2026. They threaten to expose the stolen data unless EY engages in negotiations. The breach became public knowledge earlier this month after EY detected unusual activity on April 23, 2026, within a platform used internally for tax-related client services.
Investigations revealed that unauthorized access to the platform occurred between March 28 and April 12, 2026. During this period, documents linked to numerous clients were downloaded, potentially exposing sensitive information such as names, addresses, Social Security numbers, and financial details.
Impact on Clients
EY has filed notification letters with regulatory bodies, including the Attorneys General in California and Texas, confirming that at least 1,366 residents across multiple states were affected. However, given EY’s global clientele, the true number of impacted individuals is likely higher.
Despite the breach, EY reports no evidence of the stolen data being misused and does not believe any client was specifically targeted. The firm is offering two years of complimentary credit monitoring and identity restoration services to those affected.
ShinyHunters’ Methodology
ShinyHunters’ declaration marks the first time the group has claimed this attack, previously undisclosed by EY regarding the breach method. The group added EY to its list of victims, alongside other companies like RingCentral and Brinks Home, suggesting a supply-chain attack facilitated access to EY’s systems.
This tactic is consistent with ShinyHunters’ approach, seen in previous attacks on entities such as Instructure and Charter Communications, where they exploited SaaS platforms and credentials to extract large amounts of data before demanding ransoms.
As of now, EY has not publicly confirmed ShinyHunters’ claims or addressed the impending deadline. No data from the breach has surfaced on illicit platforms, but security experts continue to monitor the situation closely.
