ShinyHunters claims Ernst & Young breach, points to supply-chain attack
The extortion crew says stolen credentials from a third-party supplier gave them access to EY's Jira, GitHub and Azure. The accounting giant has not confirmed the group's role.

Key points
- ShinyHunters, an extortion gang, has publicly claimed the Ernst & Young breach first disclosed earlier this month.
- The group listed EY on its leak site and set a payment deadline of 31 July 2026.
- Attackers accessed a third-party IT support ticket system between 28 March and 12 April, with EY detecting unusual activity on 23 April.
- Stolen support tickets may contain personal and financial information used to prepare client tax filings.
- EY is offering affected clients 24 months of identity monitoring through Experian.
ShinyHunters, a data-theft and extortion crew that has racked up claims against Snowflake customers, Ticketmaster and AT&T over the past two years, has added Ernst & Young to its leak site. The group says it broke into the accounting firm through a supplier, not through EY's front door.
EY, one of the Big Four accounting firms, disclosed the breach earlier this month. The firm said a third-party support ticket system used by its IT staff was accessed and that tickets containing client tax information were taken.
The intruders were inside the platform from 28 March to 12 April, according to EY. Unusual activity was spotted on 23 April. The firm has not named the compromised system, said how many people were affected, or detailed the categories of information exposed.
Who are ShinyHunters?
ShinyHunters is a criminal group that steals corporate data and then demands payment to keep it off the internet. They do not encrypt files like traditional ransomware, which is malicious software that locks a victim's systems until money is paid. They simply threaten to publish what they took.
The crew has been linked to a long list of high-profile thefts, often working through cloud accounts and developer tools rather than through crude email attacks.
How did they say they got in?
The group told BleepingComputer that EY credentials were harvested through a supply-chain attack, meaning they broke into a supplier first and then used what they found there to walk into EY. Those stolen logins, they claim, opened the door to EY's Jira (a project-tracking tool used by software teams), its GitHub code repositories, and its Azure cloud environment.
The hackers would not name the supplier and would not describe exactly what data they took. They say the tax-related documents EY has already acknowledged are part of the haul, along with more that has not been disclosed.
EY has not confirmed that ShinyHunters is behind the attack. The firm previously said it removed the unauthorised access, secured its systems, and notified federal law enforcement.
What was taken, and who is affected?
| Detail | What EY has said |
|---|---|
| Access window | 28 March to 12 April |
| Detected | 23 April |
| System hit | Unnamed third-party IT support platform |
| Data type | Personal and financial information from tax filings |
| People affected | Not disclosed |
| Support offered | 24 months identity monitoring via Experian |
The leaked tickets were the kind IT staff open when helping tax teams do their work. That means the documents can include the sort of paperwork people hand over to prepare a return: names, addresses, income figures, sometimes national tax numbers.
Should EY clients be worried?
Clients whose files were caught up in the breach should already have heard from EY or expect to soon. If you are offered the free 24 months of Experian monitoring, take it. Watch for tax-themed scam calls and emails, since criminals with tax paperwork can make very convincing approaches.
The deadline ShinyHunters has set, 31 July 2026, is unusually far off for this kind of extortion. That gives EY time. It also gives the group leverage to keep the threat hanging over the firm's head for months.



