Ernst & Young (EY) is facing a claimed extortion campaign from ShinyHunters, which says it stole employee credentials and sensitive files and has threatened to leak the data unless the firm makes contact by July 31. A posting attributed to the group warned of both public data exposure and additional digital disruption, while identifying ey.com as the affected domain.
The claim follows EY's earlier disclosure that attackers gained unauthorized access to a third-party IT service management platform between March 28 and April 12, 2026, with anomalous activity detected on April 23. EY said documents linked to numerous tax clients were downloaded from support tickets containing tax records and personal and financial data, including names, addresses, Social Security numbers, and payment card details. The firm notified regulators in California and Texas, said at least 1,366 residents across multiple U.S. states were affected, and offered two years of credit monitoring and identity restoration; EY has not confirmed ShinyHunters' involvement, and no leaked data had been observed on underground forums at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
EY notified regulators including the California and Texas Attorneys General about the incident. The company confirmed at least 1,366 affected residents across multiple U.S. states and offered two years of credit monitoring and identity restoration services.
ShinyHunters publicly claimed responsibility for the EY breach and threatened to release stolen data unless EY negotiated by July 31, 2026. The group alleged it stole employee credentials and sensitive files, though EY had not confirmed the gang's claims.
A breach listing attributed to ShinyHunters reported Ernst & Young as a victim on July 27, 2026, identifying ey.com as the affected domain. The listing stated the breach occurred at 11:10 UTC and was discovered at 12:58 UTC.
EY reported that anomalous activity related to the compromised IT service management platform was detected on April 23, 2026. The company later tied the activity to unauthorized access affecting support-ticket data.
EY said the unauthorized access to the IT service management platform continued until April 12, 2026. During the incident, documents tied to numerous tax clients were downloaded.
EY disclosed that unauthorized access to an IT service management platform began on March 28, 2026. ShinyHunters later alleged the intrusion involved a supply-chain compromise of a third-party IT support platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcebusinessinsurance.com
Open sourcecybersecuritynews.com
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.