ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak
The cybercriminal group ShinyHunters has alleged a breach of Ernst & Young (EY), claiming to have stolen sensitive client data and threatening to publish it on the dark web if demands are not met. On July 29, 2026, the group announced the attack via a Telegram channel, sharing sample screenshots of purportedly stolen data to pressure EY into negotiations. If no agreement is reached, ShinyHunters warned the data would be released starting July 31, 2026.
According to EY’s incident response investigation, unauthorized access likely occurred between March 28 and April 12, 2026, during which attackers allegedly exfiltrated tax return files and other confidential client documents. The full extent of the breach remains undisclosed, including the number of affected clients.
The incident poses significant risks, as exposed financial and personal data could lead to identity theft, fraud, and targeted phishing attacks. ShinyHunters, known for high-profile extortion campaigns, has previously targeted large organizations across industries, using public leaks and dark web postings to coerce victims.
Cybersecurity experts are assessing the authenticity of the leaked samples while investigations continue. No further verified details have been confirmed beyond the attackers’ claims and EY’s preliminary findings.
EY cybersecurity rating report: https://www.rankiteo.com/company/ernstandyoung
"id": "ERN1785357267",
"linkid": "ernstandyoung",
"type": "Breach",
"date": "3/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Professional Services '
'(Accounting/Consulting)',
'name': 'Ernst & Young (EY)',
'size': 'Large',
'type': 'Organization'}],
'data_breach': {'data_exfiltration': True,
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Tax return files',
'Confidential client documents']},
'date_detected': '2026-07-29',
'date_publicly_disclosed': '2026-07-29',
'description': 'The cybercriminal group ShinyHunters has alleged a breach of '
'Ernst & Young (EY), claiming to have stolen sensitive client '
'data and threatening to publish it on the dark web if demands '
'are not met. Unauthorized access likely occurred between '
'March 28 and April 12, 2026, during which attackers allegedly '
'exfiltrated tax return files and other confidential client '
'documents. The incident poses risks of identity theft, fraud, '
'and targeted phishing attacks.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': 'Tax return files and other confidential '
'client documents',
'identity_theft_risk': 'High'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'ransomware': {'data_exfiltration': True},
'references': [{'date_accessed': '2026-07-29',
'source': 'Telegram (ShinyHunters announcement)'}],
'threat_actor': 'ShinyHunters',
'title': 'ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak',
'type': 'Data Breach'}