The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company’s systems via a supply-chain attack.
Ernst & Young disclosed the breach earlier this month, saying a third-party support ticket system used by its IT personnel was compromised and support tickets that may contain client tax information were stolen.
EY says it detected unusual activity on April 23 and determined that the attacker accessed the platform between March 28 and April 12, downloading multiple documents.
“EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients,” reads the EY data breach notification.
“Support tickets submitted through the platform may include documents containing client tax information”
The notification goes on to say that the stolen documents contained personal and financial information included in or used to prepare tax filings.
However, the company has not disclosed the name of the compromised support system, the specific types of information exposed, or how many people were affected.
At the time the breach was disclosed, no ransomware or data extortion group had claimed responsibility for the attack.
Today, the ShinyHunters extortion gang added Ernst & Young to its data leak site, claiming it conducted the attack and threatened to release the allegedly stolen data if the company does not contact the group by July 31, 2026.
The threat actors claimed to BleepingComputer that EY credentials were obtained through a supply-chain attack and used to breach the company. These stolen credentials allegedly allowed them to breach Ernst & Young’s Jira, GitHub, and Azure environments.
The threat actor would not identify the allegedly compromised third party or disclose what data was stolen. However, it claimed that the information EY acknowledged as compromised was exposed, along with more data.
BleepingComputer has no way to verify the threat actor’s claims independently, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.
BleepingComputer contacted Ernst & Young again Monday morning to ask whether ShinyHunters was behind the attack and whether the company had received an extortion demand from the group.
We also asked EY to identify the compromised support system and disclose how many people were affected by the breach.
Ernst & Young previously said it secured its systems, removed the unauthorized access, and notified federal law enforcement.
Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
ShinyHunters data leaks fuel $2,000 sextortion email scam
Abbott probes two cyber incidents amid extortion claims
Medtronic notifies customers impacted by ShinyHunters data breach
Kodak confirms data breach claimed by ShinyHunters extortion gang
OpenAI confirms ChatGPT is down worldwide
Malicious sites use JavaScript to build malware in browser memory
ShinyHunters data leaks fuel $2,000 sextortion email scam
Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.
Uncover shadow AI apps, agents, and risky data sharing. Get started in 5 min.
AI agents can speed up ransomware attacks. See how Acronis helps reduce the risk.
Overdue a password health-check? Audit your Active Directory for free
Rev5 is ending. See what your FedRAMP 20x transition really requires
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



