AIO APEX

ShinyHunters claims Ernst & Young breach, threatens to dump stolen tax data by July 31

BleepingComputer
Share:
ShinyHunters claims Ernst & Young breach, threatens to dump stolen tax data by July 31

The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, setting a July 31 deadline for the firm to make contact or face public release of the stolen data. The gang says it obtained EY credentials through a supply-chain attack, using them to access the company's Jira, GitHub, and Azure environments — going significantly deeper than the third-party support ticket system EY publicly acknowledged was compromised, as reported by BleepingComputer.

Ernst & Young disclosed the breach earlier this month, confirming that a third-party IT service management platform — used by EY personnel to support tax-related work — was compromised. The company detected unusual activity on April 23 and determined that unauthorized access occurred between March 28 and April 12, 2026. During that window, an attacker downloaded multiple documents containing support tickets that may include client tax information, along with personal and financial data used to prepare tax filings.

EY has not disclosed how many clients were affected, the name of the compromised support system, or the specific types of information exposed beyond what was required in breach notification filings. Affected clients are being offered 24 months of identity monitoring through Experian, and federal law enforcement has been notified.

ShinyHunters Claims Wider Access

ShinyHunters told BleepingComputer that the stolen credentials from the supply-chain attack went beyond the support ticket platform, giving them access to EY's Jira project management system, GitHub code repositories, and Azure cloud environments. If verified, this would represent a substantially larger breach than EY has publicly characterized.

Ernst & Young has not confirmed ShinyHunters' specific claims, and the extent of any access beyond the support ticket system remains unverified. The July 31 deadline is a standard extortion tactic — the gang adds companies to its leak site and publicly demands contact, with the threat of releasing stolen data as leverage.

ShinyHunters Track Record

ShinyHunters is a well-documented extortion operation with a history of targeting major organizations. The group previously claimed breaches at Ticketmaster, Santander Bank, and other large enterprises. Their method — supply-chain attacks that compromise credentials indirectly through third-party vendors — has become one of the most effective vectors for breaching large organizations with strong perimeter defenses.

EY is one of the Big Four accounting firms, serving thousands of corporate clients globally. The exposure of client tax filings — including personal income, corporate financial structures, and investment data — would carry significant consequences for any affected individuals and businesses.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: