ShinyHunters is claiming responsibility for a breach at Ernst & Young that allegedly exposed personal and financial data used for client tax filings. The group says it obtained EY credentials through a supply chain attack and used them to access the firm’s Jira, GitHub and Azure environments. If EY does not respond by 31 July 2026, ShinyHunters has threatened to publish the stolen data.
EY has not confirmed the breach, has not disclosed how many individuals are affected and has not publicly identified the attackers. That silence is a problem. Tax filing data typically includes names, addresses, national identification numbers, income figures and employer details. For clients of a Big Four firm, that means high-net-worth individuals and corporate finance teams, not generic consumer records.
What ShinyHunters Is Claiming
According to BleepingComputer and Security Affairs, ShinyHunters alleges the initial access came through a third-party supplier whose credentials were compromised and then used to pivot into EY’s own systems. The group claims those credentials provided access to internal development and cloud infrastructure, specifically Jira, GitHub and Azure. If accurate, that access would cover source code repositories, project management data and potentially cloud-hosted client data depending on how EY’s Azure tenancy is structured.
ShinyHunters has set a 31 July 2026 deadline. No ransom figure has been published. The group is demanding contact, not a specific payment which may indicate negotiations are at an earlier stage than typical ransomware disclosures.
These are the attacker’s claims. EY has not verified them. ShinyHunters has a documented history of credible breaches including Ticketmaster in 2024 and Santander Bank in the same year but they have also made exaggerated or unverifiable claims about breach scope in the past. Until EY confirms what was accessed, treat the specific claim about Jira, GitHub and Azure as unverified.
A Supply Chain Entry Point, Not a Direct Attack
The alleged attack vector matters more than the attacker’s identity. ShinyHunters is claiming they did not breach EY directly. They compromised a supplier, took credentials from that supplier and used those credentials to reach EY’s internal environment. That is the same pattern seen in the 2020 SolarWinds campaign and the 2023 MOVEit exploitation, the target organisation’s perimeter controls are irrelevant if a trusted third party provides a legitimate path in.
For any organisation using EY for tax advisory, audit or consulting work, the question is not whether EY’s own security controls were adequate. The question is whether the data EY held on your behalf was within scope of the systems the attackers reached. That answer is not yet public.
EY’s Clients Cannot Wait for a Disclosure That May Not Come
EY serves governments, financial institutions and large corporates across Europe. Nordic clients include some of the region’s largest listed companies. Deloitte, PwC, KPMG and EY collectively hold sensitive financial data for a substantial share of the Nordic business community. If stolen tax filing data surfaces publicly after the 31 July deadline, the reputational and regulatory consequences for EY’s clients will land regardless of whether EY has formally disclosed the breach.
Organisations that have shared tax filing data, payroll records or corporate financial information with EY in recent years should contact their EY account team now and ask for written confirmation of what data was held in the affected environments, whether that data was within the scope of the breach and what notification obligations EY intends to fulfil under GDPR Article 33 and 34.
Under GDPR, a data processor that becomes aware of a personal data breach must notify the relevant supervisory authority within 72 hours and, where the breach is likely to result in high risk to individuals, notify affected data subjects without undue delay. EY has not confirmed a breach but the clock on those obligations runs from when they become aware of a qualifying incident, not from when they choose to disclose it publicly. European data protection authorities will be watching how this is handled.
ShinyHunters Is Not a New Threat
ShinyHunters has been active since at least 2020. Their confirmed victim list includes Ticketmaster, Santander, AT&T and dozens of smaller targets. In June 2024, US authorities arrested a French national in Morocco believed to be a key member of the group. The arrests did not end the group’s operations. ShinyHunters continued posting breach claims through late 2024 and into 2025.
This is a group that has demonstrated the capability to breach large, well-resourced organisations and the willingness to publish data when demands are not met. The 31 July deadline is credible in the sense that they have followed through before. Whether EY’s data is as complete and sensitive as ShinyHunters claims is a separate question.
References
- Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
- ShinyHunters Claims Ernst & Young Hack
- ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data
- Pay or leak – ShinyHunters Claims EY hack
- GDPR Article 33 and 34: Notification of Personal Data Breaches
This post is also available in: