ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach, alleging it stole employee credentials and sensitive files through a supply-chain compromise of a third-party IT support platform. EY first disclosed the incident earlier this month after detecting anomalous activity on April 23, 2026, within an IT service management platform used by internal staff to support tax-related client work.

ShinyHunters' Extortion Claim The compromised support tickets often contained attached client tax documents, exposing sensitive data including: Names and addresses Social Security numbers Financial account numbers Credit and debit card details Other information used to prepare tax filings EY filed breach notification letters with regulators including the California and Texas Attorneys General, confirming a floor of at least 1,366 affected residents across multiple US states, though the firm's global client base suggests the real number is significantly higher. EY Data Breach Claimed by ShinyHunters (Source: ZeroOwl) That changed when ShinyHunters listed EY on its leak site alongside new victims RingCentral and Brink's Home, asserting the intrusion originated from a supply-chain attack that yielded credentials to EY's internal systems.

This tactic mirrors ShinyHunters' established approach in recent campaigns against Instructure, Charter Communications, and McGraw Hill, where the group exploited SaaS platforms, SSO credentials, and vishing attacks to exfiltrate large data volumes before demanding ransom.