Ernst & Young: ShinyHunters targets accounting giant EY aka Ernst & Young with Data Breach

Ernst & Young: ShinyHunters targets accounting giant EY aka Ernst & Young with Data Breach

ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak

The cybercriminal group ShinyHunters has alleged a breach of Ernst & Young (EY), claiming to have stolen sensitive client data and threatening to publish it on the dark web if demands are not met. On July 29, 2026, the group announced the attack via a Telegram channel, sharing sample screenshots of purportedly stolen data to pressure EY into negotiations. If no agreement is reached, ShinyHunters warned the data would be released starting July 31, 2026.

According to EY’s incident response investigation, unauthorized access likely occurred between March 28 and April 12, 2026, during which attackers allegedly exfiltrated tax return files and other confidential client documents. The full extent of the breach remains undisclosed, including the number of affected clients.

The incident poses significant risks, as exposed financial and personal data could lead to identity theft, fraud, and targeted phishing attacks. ShinyHunters, known for high-profile extortion campaigns, has previously targeted large organizations across industries, using public leaks and dark web postings to coerce victims.

Cybersecurity experts are assessing the authenticity of the leaked samples while investigations continue. No further verified details have been confirmed beyond the attackers’ claims and EY’s preliminary findings.

Source: https://www.cybersecurity-insiders.com/shinyhunters-targets-accounting-giant-ey-aka-ernst-young-with-data-breach/

EY cybersecurity rating report: https://www.rankiteo.com/company/ernstandyoung

"id": "ERN1785357267",
"linkid": "ernstandyoung",
"type": "Breach",
"date": "3/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Professional Services '
                                    '(Accounting/Consulting)',
                        'name': 'Ernst & Young (EY)',
                        'size': 'Large',
                        'type': 'Organization'}],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Tax return files',
                                              'Confidential client documents']},
 'date_detected': '2026-07-29',
 'date_publicly_disclosed': '2026-07-29',
 'description': 'The cybercriminal group ShinyHunters has alleged a breach of '
                'Ernst & Young (EY), claiming to have stolen sensitive client '
                'data and threatening to publish it on the dark web if demands '
                'are not met. Unauthorized access likely occurred between '
                'March 28 and April 12, 2026, during which attackers allegedly '
                'exfiltrated tax return files and other confidential client '
                'documents. The incident poses risks of identity theft, fraud, '
                'and targeted phishing attacks.',
 'impact': {'brand_reputation_impact': 'Significant',
            'data_compromised': 'Tax return files and other confidential '
                                'client documents',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing',
 'motivation': 'Extortion',
 'ransomware': {'data_exfiltration': True},
 'references': [{'date_accessed': '2026-07-29',
                 'source': 'Telegram (ShinyHunters announcement)'}],
 'threat_actor': 'ShinyHunters',
 'title': 'ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.