ShinyHunters claims EY breach, warns all stolen data will be released
"Yes it was us:" the notorious hacker collective boasted on the dark web.

Image from Gettyimages
- ShinyHunters claimed responsibility for the EY breach and threatened to leak data unless EY negotiates by July 31st.
- EY said attackers accessed a third-party platform from March 28th to April 12nd and downloaded client documents.
- The exposed files may include personal and financial tax information, raising risks of targeted phishing and fraud against EY clients.
- ShinyHunters has been tied to major breaches affecting companies including Sysco, Ralph Lauren, Cisco, Rockstar Games, and Salesforce clients.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Weeks after the accounting giant disclosed a breach involving sensitive client tax documents, the ShinyHunters ransomware gang has claimed responsibility.
ShinyHunters, the notorious ransomware gang, has claimed Ernst & Young (EY). The firm, one of the world’s largest professional services, appeared on the ransomware gang’s leak site on July 27th.
“Yes, it was us,” the attackers bragged in the post on the leak site on the dark web.
The attackers gave EY until July 31st to contact them and start negotiations, or they would publicly leak the data. According to the attackers, they have been trying to contact EY.
“If you do not come to us to talk within the given deadline, we fully and completely intend to release all the data and files,” they said.
The information about the data breach first surfaced in mid-July, when EY disclosed it and notified affected individuals through a filing with the California Department of Justice.
According to the notice, attackers compromised a third-party system used by the firm. ShinyHunters do not specify which third-party company they breached to reach EY data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Tax data may be leaked
EY's investigation determined that attackers accessed the platform between March 28th and April 12th, 2026, and downloaded documents belonging to multiple EY clients.
ShinyHunters do not specify what kind of data they have exfiltrated, nor do they provide data samples.
However, in the notice, EY said the incident involved documents that may have contained personal information and financial details related to clients’ tax filings, as support tickets submitted through the platform may include attached documents with sensitive information.
If leaked, such data may put EY clients at risk of targeted phishing campaigns. Cybercriminals could use tax and financial details to craft convincing emails or messages impersonating EY or other tax authorities.
Addressing the victim personally and holding a handful of private data increases the likelihood that the individual would disclose additional sensitive information, transfer funds, or install malware.
Who are ShinyHunters?
The primarily English-speaking extortion group has been linked to numerous high-profile breaches over recent years and has built a reputation for stealing and monetizing large datasets.
In June, the gang hit Sysco, the world’s largest food distributor, and American fashion giant Ralph Lauren.
ShinyHunters is also believed to be behind the extortion campaign targeting Oracle's PeopleSoft enterprise software.
Previously this year, the gang hit Dutch telecommunications giant Odido and the European Commission. The gang is also behind attacks on Cisco Systems, GTA creators Rockstar Games, and US investment advisory firms Mercer Advisors and Beacon Pointe Advisors.
And it was partly responsible for last year’s Salesforce heist, which was claimed by a conglomerate of 3 gangs, dubbed Scattered LAPSUS$ Hunters. ShinyHunters is a member of this trio.
The Salesforce attacks affected more than 700 other companies, including Cloudflare, Zscaler, Palo Alto Networks, Google, Allianz Life, TransUnion, Farmers Insurance, Air France, and KLM.