The ShinyHunters extortion crew has publicly claimed responsibility for the data breach at Big Four accounting firm Ernst & Young, ending three months of silence over who was behind an intrusion that exposed client tax records. EY confirmed the incident earlier in July 2026, disclosing that an unauthorized third party had access to an internal IT service management platform from March 28 to April 12, 2026, and downloaded documents belonging to numerous clients. Regulatory filings with the California and Texas Attorneys General establish a floor of at least 1,366 affected US residents, a number the firm's global client base suggests is a fraction of the true total. ShinyHunters listed EY on its dark web leak site with a "final warning" deadline of July 31, 2026.
What Happened
EY detected anomalous activity on April 23, 2026, inside an IT service management platform used by internal staff to support tax-related client work. The subsequent investigation found that the intruder's access predated detection by nearly a month, running from March 28 through April 12, 2026. During that roughly two-week window the attacker pulled down support tickets and their attachments.
The platform itself was operated by a third party, not EY. That distinction matters: the firm's own network perimeter was not the initial point of failure. EY's public disclosure did not explain how the intruders reached the platform, and no threat actor claimed the attack at the time.
That changed this week. ShinyHunters added EY to its leak site alongside other fresh victims including RingCentral and Brinks Home, asserting that the intrusion began as a supply chain compromise that yielded valid credentials into EY-facing systems. The group's notice, updated July 27, 2026, threatens to publish all stolen data and files if EY does not open negotiations by July 31.
What Was Taken
The stolen material is unusually sensitive even by breach standards, because tax preparation work concentrates the exact data set identity thieves want most. Support tickets in the compromised platform routinely carried attached client tax documents. Per EY's notification letters, the exposed fields include:
- Full names and residential addresses
- Social Security numbers
- Financial account numbers
- Credit and debit card details
- Additional supporting data used to prepare tax filings
ShinyHunters separately claims to hold employee credentials taken from the same intrusion, which would extend the impact beyond client records into EY's own access footprint.
EY states it is unaware of any misuse of the data and does not believe any individual client was specifically targeted. The firm is offering two years of credit monitoring and identity restoration to notified individuals. The 1,366 figure reflects only residents in states with mandatory AG notification thresholds; it is a reporting artifact, not a scope estimate.
Why It Matters
Professional services firms are aggregation points. A single accounting practice holds the complete financial identity of thousands of individuals and the confidential deal, audit, and tax posture of major corporations. Compromising one support platform at a Big Four firm returns more usable data than compromising dozens of individual targets.
The three month attribution gap is its own lesson. EY disclosed the breach without naming an actor or an intrusion vector, which is common and often unavoidable. But it means downstream clients spent months unable to assess whether their data was headed for a leak site or sitting in a quiet espionage collection. ShinyHunters' listing resolved that question in the worst direction.
The clustering of EY with RingCentral and Brinks Home on the same leak site update points to a campaign rather than an opportunistic hit. ShinyHunters has repeatedly demonstrated a model of compromising one platform that many enterprises trust, then monetizing the resulting tenant list one victim at a time. Organizations that share a vendor with EY should treat this listing as a warning about their own exposure.
Finally, the extortion clock is a real operational deadline. A July 31 publication threat means any client whose tax documents sat in those tickets faces a concrete near-term fraud risk window, not a theoretical one.
The Attack Technique
ShinyHunters describes the intrusion as a supply chain attack that produced credentials to EY's internal systems. That pattern is consistent with the group's established tradecraft: compromise a service provider or SaaS platform, harvest valid authentication material, then log into downstream customer environments as a legitimate user.
The observable behavior fits. Access ran for roughly sixteen days before it stopped, and detection came eleven days after the intruder left. Activity that authenticates correctly and reads data the account is entitled to read does not trip signature-based controls. The attacker did not need malware or an exploit chain; they needed a valid session against a platform that trusted them.
The chosen target within that platform is also deliberate. Support ticketing systems are a soft underbelly. They are treated as operational tooling rather than a data store, yet users attach whatever document is needed to resolve the issue. In a tax practice, that document is a tax return. The ticket queue became an unclassified repository of Social Security numbers with none of the controls that would guard a formal client data system.
EY has not corroborated ShinyHunters' account of the initial vector, and the claim should be treated as actor-supplied until the firm or a responder confirms it. Extortion groups have incentives to overstate both access and holdings.
What Organizations Should Do
-
Inventory what lives in your ticketing systems. Run content discovery across service desk platforms for SSNs, account numbers, and payment card data in ticket bodies and attachments. Most organizations find regulated data sitting in queues that were never scoped for it. Purge it and enforce retention limits on attachments.
-
Kill standing credentials for third-party support platforms. Move vendor and integration access to short-lived tokens with phishing-resistant MFA. A supply chain compromise only cashes out if the credentials it yields are still valid days later.
-
Alert on volume, not just signatures. The defining signal in this incident was a legitimate account downloading documents across many unrelated client tickets. Baseline normal per-user export and attachment-download rates in every SaaS platform you run, and alert on deviation. Sixteen days of bulk collection should not be invisible.
-
Demand intrusion telemetry in vendor contracts. Require providers to deliver authentication logs, admin action logs, and data access logs to your SIEM, not just an incident summary after the fact. Without that feed you are dependent on the vendor's own detection timeline.
-
Map your shared vendor exposure to this campaign. If your organization uses the same IT service management or support tooling categories, review the last six months of authentication logs for anomalous source addresses and unusual off-hours access from vendor accounts.
-
Pre-stage your notification and monitoring response. With a July 31 leak threat active, any organization that engaged EY for tax work should assume publication is possible, alert affected employees or clients to fraud risk now, and consider tax identity protection PINs where individual tax filings are implicated.
Sources: EY Data Breach Claimed by ShinyHunters Hacker Group