ShinyHunters Claims Responsibility for EY Data Breach
The extortion group has threatened to publish allegedly stolen information by 31 July, while its claims of access to EY’s Jira, GitHub and Azure environments remain unverified
The ShinyHunters cyber-extortion group has claimed responsibility for the recently disclosed data breach at EY’s US member firm and threatened to publish allegedly stolen information unless the firm contacts it by 31 July 2026.
The group added EY to its data-leak site on 27 July. It claimed that credentials obtained through a supply-chain compromise had enabled access to EY systems, including its Jira, GitHub and Microsoft Azure environments.
Those claims have not been independently verified. ShinyHunters did not identify the allegedly compromised supplier or provide details of the information it claims to have taken. EY has not publicly confirmed that the group carried out the intrusion or that the additional systems named by the attackers were accessed.
EY disclosed the underlying breach earlier in July. The firm said an unauthorised party had accessed a third-party IT service-management platform used by its technology personnel to support teams performing tax-related client work. The attacker was present in the platform between 28 March and 12 April, while EY detected anomalous activity on 23 April.
Support tickets submitted through the platform could contain documents holding client tax information. EY said downloaded material included personal and financial information contained in, or used to prepare, tax filings. Reported data categories include names, addresses, Social Security numbers, financial-account details and payment-card information.
The firm has not publicly identified the affected service-management platform or disclosed the total number of clients and individuals whose information may have been compromised.
EY said it had secured its systems, removed the unauthorised access, engaged independent cybersecurity specialists and notified federal law-enforcement authorities. It has offered eligible affected individuals 24 months of identity-monitoring and restoration services.
EY previously said it was not aware of any misuse or further exposure of the affected information and had no indication that particular individuals had been specifically targeted. The ShinyHunters claim introduces the possibility of an extortion attempt and wider access, but does not establish that either occurred as the group has described.
The incident has already resulted in a proposed US class action. Illinois resident Markishi Wyatt alleges that EY failed to protect sensitive tax, financial and personal information and exposed affected individuals to increased risks of identity theft and fraud. EY has not admitted those allegations, which have not been tested in court.
The 2026 incident is separate from the 2023 MOVEit breach involving information EY handled for Bank of America. EY and the bank have agreed to create a $2.5 million settlement fund in that case, although the proposed settlement remains subject to court approval.
Related Coverage
BleepingComputer: Ernst & Young data breach claimed by ShinyHunters extortion gang
Reports the group’s attribution claim, its 31 July deadline and its unverified allegations concerning access to EY’s Jira, GitHub and Azure environments.
BleepingComputer: Ernst & Young discloses data breach after support-system hack
Sets out EY’s account of the underlying intrusion, including the period of unauthorised access and the firm’s remediation measures.
SecurityWeek: Ernst & Young data breach affects personal and financial information
Details the categories of information potentially exposed through the third-party service-management platform.
Big4News: EY faces proposed US class action over client data breach
Covers the lawsuit alleging that EY failed to protect sensitive tax and financial information affected by the incident.
Big4News: EY’s data breach and the expanding attack surface of Big Four AI
Examines the breach’s wider implications for third-party risk, connected systems and the security perimeter surrounding Big Four technology platforms.
Trying to keep up with technology at Deloitte, PwC, EY and KPMG? Start here →
https://www.big4news.com/t/technology-and-ai
Want to stay up to date on all things Big Four around the world?
Check out the News section and subscribe to Big4News for weekly deep dives and briefings.



