
The cybercriminal group ShinyHunters has claimed responsibility for a cyberattack targeting global accounting and professional services firm Ernst & Young (EY). According to the group’s public announcement, it has allegedly gained unauthorized access to EY’s systems and stolen sensitive client data, threatening to publish the information on the dark web if its demands are not met.
On July 29, 2026, the hacking group released a statement through one of its Telegram channels, claiming that it had successfully breached EY’s servers. To support its claims, the attackers also published several sample screenshots that they allege contain stolen client information. The screenshots were shared on a website reportedly operated by the group, apparently to demonstrate that the data was authentic and to increase pressure on the organization.
ShinyHunters has given EY an ultimatum, urging the company to enter into negotiations. The group warned that if the organization refuses to engage or fails to meet its demands, the allegedly stolen data will be published on the dark web beginning July 31, 2026. Such tactics are commonly used by cybercriminal groups involved in extortion campaigns, where the threat of exposing confidential information is used to pressure victims into paying a ransom or negotiating a settlement.
According to information attributed to EY’s incident response investigation, unauthorized access to the company’s servers is believed to have occurred between March 28, 2026, and April 12, 2026. During this period, the attackers allegedly accessed and downloaded tax return files and other potentially sensitive client documents. The full scope of the data exposure has not yet been publicly disclosed, and it remains unclear how many clients may have been affected.
If confirmed, the incident could have significant consequences for both EY and its clients. Tax records and financial documents often contain highly sensitive personal and corporate information, making them valuable targets for cybercriminals. The exposure of such data could increase the risk of identity theft, financial fraud, and targeted phishing attacks against affected individuals and organizations.
ShinyHunters has been linked to several high-profile cyber incidents in recent years and is known for targeting large organizations across multiple industries. The group has frequently used data theft and public leak threats as part of its extortion strategy, often leveraging messaging platforms and dark web leak sites to publicize its claims and pressure victims.
As investigations continue, cybersecurity experts are closely monitoring the situation to determine the authenticity of the leaked samples and assess the overall impact of the alleged breach. Organizations are reminded of the importance of continuous security monitoring, timely incident response, strong access controls, and employee awareness programs to reduce the risk of unauthorized access and data exfiltration.
At the time of writing, no additional verified details regarding the attackers’ claims or the extent of the alleged compromise have been publicly confirmed beyond the information released by the threat actors and the reported findings of the incident response investigation.
Join our LinkedIn group Information Security Community!










