ShinyHunters Claims Ernst & Young Hack
The ShinyHunters extortion group claims responsibility for a data breach involving Ernst & Young (EY). Personal and financial information was stolen from a third-party management platform supporting EY's tax-related work. The breach occurred between March 28 and April 12, during which attackers accessed tax-related documents containing sensitive client data such as names, addresses, Social Security numbers, and financial account details. EY has notified affected individuals and is offering 24 months of credit and identity monitoring services. The company has not disclosed the number of impacted individuals or technical details about the breach. ShinyHunters has threatened to release the stolen data if EY does not respond by July 31. No patch or remediation details are available as this is a data breach incident involving a third-party platform.
AI Analysis
Technical Summary
Ernst & Young confirmed a data breach involving theft of personal and financial information from a third-party service management platform used to support tax-related work. The breach occurred between March 28 and April 12, with attackers downloading client tax documents containing sensitive information including Social Security numbers and financial account data. The ShinyHunters extortion group claimed responsibility and has posted the stolen data on their leak site, threatening further exposure. EY is providing affected individuals with credit and identity monitoring services but has not disclosed the breach's full scope or technical details. No information on the exploited vulnerability or patch availability has been provided.
Potential Impact
Sensitive personal and financial information of Ernst & Young clients was compromised, including client names, addresses, Social Security numbers, account numbers, and credit/debit card numbers. This exposure increases the risk of identity theft, financial fraud, and privacy violations for affected individuals. The breach affects trust in EY's data handling and third-party platform security. No direct information on operational impact or further exploitation is available.
Mitigation Recommendations
No patch or remediation details are available since this incident involves a breach of a third-party management platform rather than a disclosed software vulnerability. Ernst & Young is providing affected individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services. Organizations should review their third-party risk management and incident response processes. Monitor official communications from Ernst & Young and the third-party platform for updates. No immediate action is required beyond what EY is providing to impacted individuals.
ShinyHunters Claims Ernst & Young Hack
Description
The ShinyHunters extortion group claims responsibility for a data breach involving Ernst & Young (EY). Personal and financial information was stolen from a third-party management platform supporting EY's tax-related work. The breach occurred between March 28 and April 12, during which attackers accessed tax-related documents containing sensitive client data such as names, addresses, Social Security numbers, and financial account details. EY has notified affected individuals and is offering 24 months of credit and identity monitoring services. The company has not disclosed the number of impacted individuals or technical details about the breach. ShinyHunters has threatened to release the stolen data if EY does not respond by July 31. No patch or remediation details are available as this is a data breach incident involving a third-party platform.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Ernst & Young confirmed a data breach involving theft of personal and financial information from a third-party service management platform used to support tax-related work. The breach occurred between March 28 and April 12, with attackers downloading client tax documents containing sensitive information including Social Security numbers and financial account data. The ShinyHunters extortion group claimed responsibility and has posted the stolen data on their leak site, threatening further exposure. EY is providing affected individuals with credit and identity monitoring services but has not disclosed the breach's full scope or technical details. No information on the exploited vulnerability or patch availability has been provided.
Potential Impact
Sensitive personal and financial information of Ernst & Young clients was compromised, including client names, addresses, Social Security numbers, account numbers, and credit/debit card numbers. This exposure increases the risk of identity theft, financial fraud, and privacy violations for affected individuals. The breach affects trust in EY's data handling and third-party platform security. No direct information on operational impact or further exploitation is available.
Mitigation Recommendations
No patch or remediation details are available since this incident involves a breach of a third-party management platform rather than a disclosed software vulnerability. Ernst & Young is providing affected individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services. Organizations should review their third-party risk management and incident response processes. Monitor official communications from Ernst & Young and the third-party platform for updates. No immediate action is required beyond what EY is providing to impacted individuals.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/shinyhunters-claims-ernst-young-hack/","fetched":true,"fetchedAt":"2026-07-29T06:37:06.558Z","wordCount":921}
Threat ID: 6a699f929c2644c7f814da2f
Added to database: 07/29/2026, 06:37:06 UTC
Last enriched: 07/29/2026, 11:24:18 UTC
Last updated: 07/29/2026, 13:04:15 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.