The ShinyHunters extortion group — one of the most prolific threat actors of 2026 — has claimed responsibility for a data breach at Ernst & Young (EY), one of the "Big Four" global professional services and accounting firms. ShinyHunters posted a "final warning" on their dark web leak site with a ransom deadline of July 31, 2026, threatening to publish stolen data if EY does not respond.
What EY Confirmed
EY had already disclosed a breach earlier in July after detecting anomalous activity on April 23, 2026. The company's investigation found that unauthorized access occurred from March 28 to April 12, 2026 — a 15-day window of quiet data exfiltration before detection. The initially compromised system was confirmed to be a third-party IT service management platform used by staff supporting tax-related client work. EY confirmed that support tickets potentially containing client tax information were exfiltrated.
EY's response actions included:
- Securing and isolating the compromised environment
- Blocking all unauthorized access paths
- Notifying relevant regulatory authorities
- Offering 24 months of identity monitoring and restoration services through Experian to affected individuals
ShinyHunters' Claims
ShinyHunters told BleepingComputer that EY credentials were obtained by breaching the third-party support ticket platform, and those stolen credentials were then used to pivot into EY's core internal systems. The group claims to have subsequently accessed:
- Jira project management system
- GitHub repositories
- Azure cloud infrastructure
If accurate, this represents significant lateral movement from a support ticket platform into development and cloud assets — a progression consistent with ShinyHunters' known tradecraft of exploiting SaaS integration chains.
However, ShinyHunters' claim carries important caveats. Unlike typical ransomware announcements, the group's leak site post contained no technical proof — no file samples, no directory listings, and no screenshots of the alleged Jira or Azure access. This absence of supporting evidence is atypical for ShinyHunters, which usually publishes data samples to maximize extortion pressure. EY has not publicly confirmed ShinyHunters as the perpetrator, and independent verification remains pending as of the July 31 deadline.
Why This Matters
The data allegedly at risk includes sensitive client tax documents — among the most highly regulated and confidential categories of financial information that exist. EY's client base spans large multinational corporations, high-net-worth individuals, and government entities across multiple jurisdictions.
Exposure of tax records carries serious legal consequences under:
- GDPR — in EU/EEA jurisdictions
- IRS regulations — strict confidentiality requirements for US tax return data (26 U.S.C. § 7216)
- National data protection laws across EY's global footprint
For corporate clients, tax document exposure can reveal mergers and acquisitions under NDA, offshore structures, inter-company transactions, and effective tax rates — information that is commercially sensitive independent of any regulatory concern.
ShinyHunters' 2026 Pattern
ShinyHunters has been extraordinarily active in 2026, consistently targeting supply chain and SaaS integration weaknesses rather than direct network intrusions. Recent attributed incidents include:
| Target | Scale | Entry Point |
|---|---|---|
| Instructure (Canvas LMS) | Up to 275M individuals | SaaS integration |
| Charter Communications | 40M records | Microsoft Entra + Salesforce |
| McGraw Hill | Undisclosed | Third-party platform |
| Ernst & Young | Unconfirmed | IT support ticket platform |
The EY incident fits the group's established pattern of targeting professional services supply chains where third-party integrations create high-value access pathways into otherwise well-defended organizations.
Recommendations for Organizations
This incident should serve as a prompt to review supply chain security posture:
- Audit third-party platform access scopes — support ticket systems should not have credentials that can pivot to internal Jira, GitHub, or cloud environments
- Review support ticket data retention policies — client tax documents should not be stored within generic IT service management platforms
- Enforce just-in-time access for third-party support integrations
- Monitor for lateral movement indicators — unusual API calls from support platform service accounts
- Segment cloud credentials — Azure identities used by support operations should be isolated from production engineering environments
- Implement SaaS security posture management (SSPM) to continuously monitor third-party integration scopes