Particle.news
Download on the App Store

ShinyHunters Claims Ernst & Young Data Breach, Threatens July 31 Leak

This public extortion increases pressure on EY to disclose the compromised vendor.

Overview

  • EY said investigators found an unauthorized party accessed a third‑party IT service‑management platform and downloaded client tax documents between March 28 and April 12, with the firm detecting unusual activity on April 23.
  • The stolen files reportedly include highly sensitive tax and financial data such as names, addresses, Social Security numbers, bank account and payment card details that raise risks of identity theft and fraud.
  • ShinyHunters added EY to its dark‑web leak site on July 27 and publicly claimed responsibility while setting a July 31 deadline for contact, a demand EY has not confirmed or publicly acknowledged receiving.
  • EY says it secured systems, removed the unauthorized access, notified federal law enforcement, and is offering affected clients 24 months of Experian credit and identity monitoring.
  • The case highlights vendor supply‑chain exposure because EY has not named the third‑party platform or disclosed how many people were affected, and the extortion group's broader pattern of posting deadlines increases pressure on victims and regulators.