"EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients," the firm's breach notification said.
Ernst & Young disclosure and timeline
Ernst & Young disclosed earlier this month that a third-party support ticket system used by its IT personnel was compromised and that support tickets "may include documents containing client tax information." The firm said it detected unusual activity on April 23 and determined the attacker accessed the platform between March 28 and April 12, downloading multiple documents.
In its notification, EY said the stolen documents contained personal and financial information that was included in or used to prepare tax filings. The company has not named the compromised support system, described the specific types of information exposed beyond the broad categories above, or revealed how many people were affected.
EY also said it has secured its systems, removed the unauthorized access, and notified federal law enforcement. Affected clients are being offered 24 months of identity monitoring and restoration services through Experian.
ShinyHunters extortion claim and deadline
On July 27, 2026, the ShinyHunters extortion gang added Ernst & Young to its data leak site and claimed responsibility for the attack, according to the reporting. The group threatened to release the allegedly stolen data if EY did not contact the actors by July 31, 2026.
ShinyHunters told BleepingComputer the attackers obtained EY credentials through a supply-chain attack and used those credentials to breach multiple EY environments. The threat actors specifically claimed access to EY's Jira, GitHub, and Azure environments.
Details the extortionists disclosed — and withheld
The group would not identify the allegedly compromised third party or disclose what specific data it had taken. ShinyHunters claimed that the information EY acknowledged as compromised was exposed, "along with more data," but provided no independently verifiable evidence in the public reporting.
BleepingComputer reported it had no way to independently verify the threat actor's claims, and Ernst & Young has not confirmed that ShinyHunters was behind the attack.
Reporting and company follow-up
BleepingComputer said it contacted Ernst & Young again Monday morning to ask whether ShinyHunters was behind the attack and whether the company had received an extortion demand from the group. The outlet also asked EY to identify the compromised support system and to disclose how many people were affected. The reporting does not include a response to those follow-up questions.
How technologists, affected clients, and procurement leaders are likely to respond
- Technologists and security teams — They will focus on the claim that credentials were obtained via a supply-chain attack and used to access Jira, GitHub, and Azure environments, and on validating whether third-party service credentials were exposed or misused inside EY's environment.
- Affected clients — They are already being offered 24 months of identity monitoring and restoration services through Experian, per EY's notification; clients will be watching for further detail on which records and tax documents were involved.
- Procurement and vendor-risk leaders — The undisclosed identity of the third-party support system and the extortion timeline that ends July 31, 2026 will likely sharpen attention on supply-chain security, contractual obligations for breach notification, and the resilience of third-party service providers.
The public facts reported so far leave three concrete milestones to watch: whether Ernst & Young confirms ShinyHunters' claim, whether EY names the compromised support system and the number of affected individuals, and whether the extortionists make good on their July 31, 2026 deadline. Until those specifics are disclosed or independently verified, the record rests on EY's original notification, the ShinyHunters posting, and BleepingComputer's follow-up reporting.




