Protect.Computer
NEWS

ShinyHunters Claim Ernst & Young Breach, Threaten Tax Data Leak

· 2 min read · Data hijack Got hacked
ShinyHunters Claim Ernst & Young Breach, Threaten Tax Data Leak

The extortion crew known as ShinyHunters — the same group that has been shaking down large brands all year — now claims to have stolen sensitive data from Ernst & Young (EY), one of the world’s four largest accounting and tax-advisory firms. The gang alleges it got in through a supply-chain attack on EY’s software vendors, then pivoted into internal systems including Jira, GitHub, and Azure, and pulled documents from a third-party support platform used by clients. Among the stolen files, they say, are support tickets containing client tax information and personal financial documents. ShinyHunters has given EY a deadline of July 31, 2026 to negotiate a payment or watch the data get published.

EY has publicly acknowledged that it detected unusual activity on April 23 and that attackers were inside its third-party support platform between March 28 and April 12, but has not confirmed ShinyHunters’ role, the scope of the theft, or how many people are affected. It says it removed the intruders, secured the platform, and notified law enforcement. At this stage the incident is a claim under active dispute, not a fully confirmed breach — but if the ShinyHunters files hit a leak site next week, anyone whose tax paperwork was ever routed through EY’s client-support portal may find their financial details in criminal hands.

How to check if you’re affected

Affected products are EY’s client-support platform used by companies that engage EY for tax, audit, or advisory work — this is a business-to-business incident, so most individuals are only exposed via their employer or via personal tax filings that a company or EY office processed on their behalf. If you personally file taxes with EY (private-client, expat, or estate-planning services), watch for a breach-notification letter in the coming weeks and treat any email that names you personally, references your tax return, or asks you to “verify” a document as high-risk phishing. If your employer uses EY, ask your HR or finance team whether any of your personal data — social security number, salary, bank account, address — was in support tickets during March–April 2026; only they can answer that. In all cases, do not click attachments in unexpected emails about “your EY case” or “tax refund,” and use free credit-monitoring or a credit freeze if you’re in the US and want extra insurance against identity theft.

Sources

Related reading