Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Pay or leak! ShinyHunters claim EY hack

Infamous cyber extortion group ShinyHunters gives the professional services giant until the end of the month to pay up or face a data leak.

Tue, 28 Jul 2026
Pay or leak! ShinyHunters claims EY hack

“Yes, it was us.”

That’s how the ShinyHunters extortion group claimed responsibility for a cyber incident first disclosed by big four accounting firm EY earlier this month.

“Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files,” ShinyHunters said in a 27 July post to its darknet leak site.

 
 

“This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline.”

EY was one of three companies listed by the hackers on that date.

A ShinyHunters spokesperson also reached out to media outlet Bleeping Computer with more information regarding the incident.

“The threat actors claimed to BleepingComputer that EY credentials were obtained through a supply-chain attack and used to breach the company,” Bleeping Computer said in an article published soon after ShinyHunters’ leak post went live.

“These stolen credentials allegedly allowed them to breach Ernst & Young’s Jira, GitHub, and Azure environments.”

Cyber Daily has reached out to EY for further comment regarding the hackers’ claims.

What happened?

EY notified its clients earlier in July that some of their data had been compromised by a cyber security breach affecting one of its third-party data platforms, which the firm used to collect and store client investment data for tax-related services.

“On April 23, 2026, EY identified anomalous activity within that platform,” EY told its clients in a 13 July letter and subsequently filed with the California Attorney General’s Office.

The individual data compromised is described on a per-client basis in the letter, with placeholder text in the version filed with California’s Attorney General. However, Cyber Daily understands the data includes personal details, Social Security numbers, credit card details, and – according to the letter – “certain financial information contained or used to prepare tax filings”.

Who are ShinyHunters?

ShinyHunters is a prolific hacking group responsible for a raft of third-party compromises.

It was previously linked to a hacking group called Scattered Lapsus$ Hunters, which formed in August 2025 and was responsible for several Salesforce-related compromises. ShinyHunters itself dates back to 2019.

The group is known for its technical and social engineering skills, and its membership is thought to be largely English-speaking young men. Previous victims include Qantas, Jaguar Land Rover, PornHub, and SoundCloud.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.