ShinyHunters Claims Ernst & Young Hack
ShinyHunters claims responsibility for Ernst & Young data breach affecting tax clients.
Summary
The ShinyHunters extortion group has claimed responsibility for a recent Ernst & Young data breach in which attackers stole personal and financial information from a third-party service management platform between March 28 and April 12. Compromised data includes client names, addresses, Social Security numbers, account numbers, and credit/debit card information used for tax filings. ShinyHunters has posted EY on its Tor-based leak site and threatened to release all stolen data unless the company makes contact by July 31.
Full text
The infamous ShinyHunters extortion group has claimed responsibility for the recently disclosed Ernst & Young (EY) data breach. Earlier this month, the professional services giant reported to the Attorney General’s Offices in several states that hackers stole personal and financial information from a third-party service management platform used to support tax-related work. Between March 28 and April 12, the company said, the attackers downloaded the tax-related documents of Ernst & Young clients that were included in support tickets submitted through the platform. Client names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used for tax filings were compromised in the data breach. The company is providing the potentially impacted individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services. Ernst & Young has not shared details on the number of potentially affected individuals, nor did it say who was behind the attack. The company has not responded to a SecurityWeek inquiry on the matter.Advertisement. Scroll to continue reading. On Monday, ShinyHunters added the professional services firm to its Tor-based leak site, threatening to release all the stolen data if Ernst & Young does not make contact by July 31. With a history of following through on its threats, the extortion group has been linked to multiple high-profile data breaches recently, including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns. Related: Origin Energy Data Breach Affects 900,000 Australians Related: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack Related: MCBS Data Breach Affects 1.2 Million Individuals Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Google Adopts New Threat Actor Naming SystemUnpatched Fastjson Vulnerability Exploited in AttacksCritical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-DayNew GitHub, PyPI Policies Boost Supply Chain SecurityPTC Windchill Vulnerability Exploited in Ransomware CampaignBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsDentaQuest Data Breach Potentially Impacts Over 23 Million People Latest News Dozens of Minnesota Water Utilities Targeted in Coordinated OT AttacksCyera Acquiring Oasis Security in $1 Billion DealApple Patches 87 Vulnerabilities in iOS, 155 in macOS TahoeOT Security Startup Frenos Raises $1.52 MillionMicrosoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model Act Security Emerges from Stealth to Fight the Patch ProblemHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerHush Security Raises $30 Million for AI Agent Governance Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveBarry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email