A major accounting firm’s sensitive client data has been compromised in a recent data breach, with the notorious ShinyHunters extortion gang claiming responsibility for the attack. Ernst & Young (EY), one of the world’s largest professional services firms, disclosed the breach earlier this month, revealing that an attacker had accessed its third-party support ticket system between March 28 and April 12. The stolen data includes personal and financial information used in tax filings.
According to EY’s notification, the compromised platform is a third-party IT service management tool used by the company’s IT personnel to provide support for tax-related work. Support tickets submitted through this platform may contain sensitive client information, including documents with personal and financial details. While the firm has not disclosed the name of the specific system or how many individuals were affected, it did acknowledge that the stolen data includes client tax information.
ShinyHunters, a notorious extortion gang known for breaching multiple high-profile organizations in recent months, claimed responsibility for the attack on July 27, 2026. The group alleged that they obtained EY’s credentials through a supply-chain attack and used them to breach various systems, including Jira, GitHub, and Azure environments. In a chilling threat, ShinyHunters warned Ernst & Young that it would release the allegedly stolen data if the company does not contact the group by July 31, 2026.
While EY has confirmed that an attack occurred and that sensitive client information was compromised, the company has yet to confirm whether ShinyHunters was indeed behind the breach. In a statement to BleepingComputer, Ernst & Young said it secured its systems, removed unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
This latest development highlights the ongoing threat posed by supply-chain attacks, where hackers target third-party vendors or service providers to gain access to sensitive systems. As more organizations rely on cloud-based platforms and external services, the risk of these types of attacks continues to grow. To mitigate this risk, it’s essential for companies like EY to implement robust security measures and regularly test their defenses.
In light of this breach, we urge all readers to be vigilant about protecting their sensitive information. If you’re a client of Ernst & Young or have concerns about data breaches in general, consider taking proactive steps to safeguard your personal and financial data. Regularly review your account statements, monitor your credit reports, and stay informed about potential threats to prevent becoming the next victim of a cyberattack.
Source: Bleeping Computer — 2026-07-27