ShinyHunters claims responsibility for EY data breach
ShinyHunters claimed responsibility for a breach of Ernst & Young; attackers downloaded clients’ tax documents, including SSNs and account numbers, March 28–April 12.
ShinyHunters claimed responsibility for a breach that allowed attackers to download Ernst & Young clients’ tax documents from a third-party service management platform between March 28 and April 12. The extortion group posted EY on its Tor-based leak site and set a July 31 deadline to contact it before publishing the files.
In filings to state attorneys general, EY reported that the extracted materials included client names and addresses, Social Security numbers, account numbers, credit and debit card numbers, and other information used in tax filings.
Ernst & Young is offering potentially affected individuals 24 months of free credit monitoring, identity monitoring and identity restoration services. The company reported the incident to several state attorneys general and is investigating the matter.
EY has not disclosed the number of affected clients, the identity of the third-party vendor, or a public breakdown of which clients or jurisdictions were impacted. The firm described the incident as a compromise of a third-party service used to support tax-related activity rather than a direct breach of its internal systems.
ShinyHunters has published stolen data in past extortion campaigns and has been linked to breaches at multiple organizations, including a university, healthcare providers, a convenience-store chain, a medical device maker, a resort operator, and incidents involving Oracle PeopleSoft and Salesforce installations.
EY’s filings to state regulators are the primary public account of the scope and timeline so far. The company continues to investigate and notify affected parties.








