Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2094+ Articles
154+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
NEWS

Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang

The ShinyHunters extortion group has claimed responsibility for a supply chain attack against Ernst & Young, alleging access to the Big Four firm's Jira, GitHub, and Azure environments via a compromised third-party IT support platform. EY confirmed an April breach involving a third-party system and client tax documents.

Dylan H.

News Desk

July 28, 2026
4 min read

The ShinyHunters extortion group — one of the most prolific threat actors of 2026 — has claimed responsibility for a data breach at Ernst & Young (EY), one of the "Big Four" global professional services and accounting firms. ShinyHunters posted a "final warning" on their dark web leak site with a ransom deadline of July 31, 2026, threatening to publish stolen data if EY does not respond.

What EY Confirmed

EY had already disclosed a breach earlier in July after detecting anomalous activity on April 23, 2026. The company's investigation found that unauthorized access occurred from March 28 to April 12, 2026 — a 15-day window of quiet data exfiltration before detection. The initially compromised system was confirmed to be a third-party IT service management platform used by staff supporting tax-related client work. EY confirmed that support tickets potentially containing client tax information were exfiltrated.

EY's response actions included:

  • Securing and isolating the compromised environment
  • Blocking all unauthorized access paths
  • Notifying relevant regulatory authorities
  • Offering 24 months of identity monitoring and restoration services through Experian to affected individuals

ShinyHunters' Claims

ShinyHunters told BleepingComputer that EY credentials were obtained by breaching the third-party support ticket platform, and those stolen credentials were then used to pivot into EY's core internal systems. The group claims to have subsequently accessed:

  • Jira project management system
  • GitHub repositories
  • Azure cloud infrastructure

If accurate, this represents significant lateral movement from a support ticket platform into development and cloud assets — a progression consistent with ShinyHunters' known tradecraft of exploiting SaaS integration chains.

However, ShinyHunters' claim carries important caveats. Unlike typical ransomware announcements, the group's leak site post contained no technical proof — no file samples, no directory listings, and no screenshots of the alleged Jira or Azure access. This absence of supporting evidence is atypical for ShinyHunters, which usually publishes data samples to maximize extortion pressure. EY has not publicly confirmed ShinyHunters as the perpetrator, and independent verification remains pending as of the July 31 deadline.

Why This Matters

The data allegedly at risk includes sensitive client tax documents — among the most highly regulated and confidential categories of financial information that exist. EY's client base spans large multinational corporations, high-net-worth individuals, and government entities across multiple jurisdictions.

Exposure of tax records carries serious legal consequences under:

  • GDPR — in EU/EEA jurisdictions
  • IRS regulations — strict confidentiality requirements for US tax return data (26 U.S.C. § 7216)
  • National data protection laws across EY's global footprint

For corporate clients, tax document exposure can reveal mergers and acquisitions under NDA, offshore structures, inter-company transactions, and effective tax rates — information that is commercially sensitive independent of any regulatory concern.

ShinyHunters' 2026 Pattern

ShinyHunters has been extraordinarily active in 2026, consistently targeting supply chain and SaaS integration weaknesses rather than direct network intrusions. Recent attributed incidents include:

TargetScaleEntry Point
Instructure (Canvas LMS)Up to 275M individualsSaaS integration
Charter Communications40M recordsMicrosoft Entra + Salesforce
McGraw HillUndisclosedThird-party platform
Ernst & YoungUnconfirmedIT support ticket platform

The EY incident fits the group's established pattern of targeting professional services supply chains where third-party integrations create high-value access pathways into otherwise well-defended organizations.

Recommendations for Organizations

This incident should serve as a prompt to review supply chain security posture:

  1. Audit third-party platform access scopes — support ticket systems should not have credentials that can pivot to internal Jira, GitHub, or cloud environments
  2. Review support ticket data retention policies — client tax documents should not be stored within generic IT service management platforms
  3. Enforce just-in-time access for third-party support integrations
  4. Monitor for lateral movement indicators — unusual API calls from support platform service accounts
  5. Segment cloud credentials — Azure identities used by support operations should be isolated from production engineering environments
  6. Implement SaaS security posture management (SSPM) to continuously monitor third-party integration scopes

References

  • BleepingComputer — Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
  • CyberSecurityNews — EY Data Breach Claimed by ShinyHunters Hacker Group
  • CyberPress — ShinyHunters Claims Supply Chain Attack Exposed EY Client Tax Documents
#Data Breach#ShinyHunters#Ernst Young#Supply Chain#Extortion#Professional Services

Related Articles

LastPass Confirms Data Breach in Klue Supply Chain Attack

The Icarus extortion group compromised Klue, an AI-powered competitive intelligence platform, harvesting OAuth tokens to drain CRM data from hundreds of...

4 min read

Nintendo Confirms Employee Data Stolen in TinyPulse Cyberattack by Shadowbyt3$

Nintendo of America has confirmed that approximately 1GB of employee data — including W-9 forms, bank statements, and HR survey responses — was...

5 min read

Council of Europe Investigates ShinyHunters Data Breach Claims

The Council of Europe, Europe's oldest intergovernmental body, is probing data breach claims made by the ShinyHunters extortion group, which claimed...

5 min read
Back to all News