DATA BREACH

ShinyHunters Claims Ernst & Young Breach, Sets July 31 Extortion Deadline

The ShinyHunters extortion gang says it stole client tax records from Ernst & Young after compromising a third-party IT support platform. EY has confirmed a breach but not the attribution, and offered clients 24 months of Experian monitoring.

Matt Lucas  |  July 27, 2026  |  5 min
Editorial hero illustration
Jul 31
Extortion deadline
16 days
Intrusion window (Mar 28-Apr 12)
24 mo
Identity monitoring offered
3
Environments claimed (Jira, GitHub, Azure)
TL;DR
  • What: ShinyHunters publicly claimed on July 27, 2026 that it breached Ernst & Young through a third-party IT service management platform used for support tickets, exfiltrating documents with client tax information.
  • Impact: The gang claims access to EY's Jira, GitHub, and Azure environments and to personal and financial data used to prepare client tax filings, with an extortion deadline of July 31, 2026.
  • Fix / mitigation: There is no CVE or patch here; EY says it secured its systems, removed the unauthorized access, notified federal law enforcement, and offered affected clients 24 months of Experian identity monitoring.
  • Who's at risk: EY's tax and advisory clients whose personal and financial filing data flowed through the compromised third-party support platform.

Ernst & Young, one of the Big Four accounting firms, is now on the wrong side of an extortion clock. On July 27, 2026, the ShinyHunters extortion gang publicly claimed responsibility for a breach of EY, saying it walked out with documents containing client tax information: the personal and financial data firms like EY collect to prepare filings. The gang set a deadline of July 31, 2026. EY has confirmed a breach but has not confirmed that ShinyHunters is behind it.

The detail that should get every IT leader's attention is not who EY is. It's how the attackers say they got in. According to ShinyHunters, they did not breach EY directly. They stole credentials in a supply-chain attack against an unidentified third party, then used those credentials to reach EY's own systems through a third-party IT service management platform the firm uses for support tickets. Per the account reported by BleepingComputer's Lawrence Abrams, the attackers claim that access extended into EY's Jira, GitHub, and Azure environments.

The timeline

The intrusion window runs from March 28 to April 12. EY did not spot unusual activity until April 23, roughly eleven days after the attackers say they were done. Disclosure came earlier in July 2026, and ShinyHunters' public claim landed on July 27 with a four-day countdown to July 31. That sequence, quiet compromise, delayed detection, months-later disclosure, then a named gang forcing the issue publicly, is the modern extortion playbook in miniature.

The blast radius is other people's data

The stolen material is not EY's internal HR files. It is client tax information, the personal and financial data used to prepare tax filings. When an accounting or advisory firm is breached, the victims are downstream: the clients who trusted the firm with their most sensitive records. That is why EY is offering 24 months of Experian identity monitoring.

What EY has and hasn't said

EY says it secured its systems, removed the unauthorized access, and notified federal law enforcement. It has offered affected clients 24 months of identity monitoring through Experian. What it has not done is confirm ShinyHunters' involvement, disclose the specific compromised support system, or put a number on how many individuals are affected or how much data left the building. No record count. No data volume. That silence is itself information: either EY does not yet know the scope, or it is not saying.

The RedEye take

This breach is a clean illustration of a truth most enterprises still underprice: your attack surface includes every vendor that holds a valid credential to your environment. EY did not have to be careless for this to happen. Per ShinyHunters' own account, the failure originated at a third party, and the support platform became the bridge. A firm the size of EY runs a mature security program. It still got reached through the seams between organizations, and the attackers' first stop inside was reportedly the developer and cloud stack, Jira, GitHub, and Azure, which is exactly where you'd go to find more credentials and more data.

We'd also flag the detection gap. Sixteen days of access, and unusual activity wasn't noticed until April 23, after the attackers say the window had already closed. Extortion crews like ShinyHunters count on that lag. By the time you're reading their post, the data is already gone; the deadline is theater to convert a completed theft into a payment. Treat the July 31 date as a negotiation lever, not a technical event, and do not let it stampede your response.

What defenders should learn

Bottom line

No CVE, no patch, no exploit to chase. Just stolen credentials, a trusted third-party support platform, and 16 days of quiet access into a Big Four firm's client tax data. The defensive work is unglamorous: know your privileged vendor paths, constrain them, and watch identity. Source: BleepingComputer, "Ernst and Young data breach claimed by ShinyHunters extortion gang," Lawrence Abrams, July 27, 2026.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us