ShinyHunters Claims Ernst & Young Hack

ShinyHunters Claims Responsibility for Ernst & Young Data Breach, Threatens to Release Stolen Data

Professional services giant Ernst & Young has been hit by another high-profile data breach, this time at the hands of notorious extortion group ShinyHunters. The attackers claim to have compromised sensitive information from a third-party service management platform used by EY for tax-related work.

The breach is believed to have occurred between March 28 and April 12, during which hackers downloaded tax-related documents from support tickets submitted through the platform. This included client names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used for tax filings. While EY has not disclosed the number of individuals affected by the breach, it’s clear that a significant number of clients’ sensitive data is now in the hands of ShinyHunters.

The extortion group has a history of following through on its threats, having been linked to several high-profile data breaches in recent months. Its latest move sees EY added to the group’s Tor-based leak site, with the attackers threatening to release all the stolen data unless contact is made by July 31. Given ShinyHunters’ track record, it’s likely that the company will face significant pressure from the attackers until then.

ShinyHunters has been making waves in the cybersecurity world with its brazen attacks on companies like University of Nottingham, DentaQuest, and Medtronic. What sets these breaches apart is the group’s willingness to release sensitive data online unless a ransom is paid or other demands are met. This tactic puts not only the affected organizations but also their clients at risk of identity theft and financial loss.

For those who may be unfamiliar with ShinyHunters, it’s worth noting that the group operates by exploiting vulnerabilities in third-party platforms used by companies to manage sensitive data. By compromising these platforms, attackers can gain access to vast amounts of information, which is then used as leverage for extortion. This type of attack highlights the importance of robust security measures and regular vulnerability testing across all third-party systems.

As EY faces this latest threat, it’s essential that other organizations take note of the risks posed by ShinyHunters and similar groups. The takeaway here is that no company is immune to data breaches, especially when they rely on external platforms for sensitive operations. By implementing robust security measures, conducting regular vulnerability testing, and staying vigilant in the face of emerging threats, companies can reduce their exposure to these types of attacks.

For readers who may be impacted by this breach, it’s crucial to remain informed about any services provided by EY, such as credit monitoring or identity restoration. Additionally, keeping a close eye on financial statements and credit reports can help identify any suspicious activity related to the compromised data.


Source: SecurityWeek — 2026-07-29