Escalating security crisis: ShinyHunters issues final ultimatum to EY
- Thảo Nguyên

- 1 day ago
- 4 min read
Ernst & Young (EY), one of the largest names in the global consulting and auditing industry, is facing a severe cybersecurity challenge. The notorious extortion group ShinyHunters recently publicly claimed responsibility for the data leak at EY. The hacker group asserts that it has compromised employee credentials and various sensitive internal documents by executing a supply chain attack on a third-party IT support provider.
The announcement was posted directly on the group's dark web data leak site, accompanied by a "final warning" threat. ShinyHunters has set a deadline of July 31, 2026, for EY to enter negotiations, failing which all stolen data and files will be leaked online.
The progression of the EY system intrusion
Earlier this month, EY proactively disclosed the incident after its systems recorded anomalies on April 23, 2026. The breached area was an internal IT service management platform used by employees to handle and support client tax-related matters.
Subsequent investigations determined that an unauthorized third party successfully accessed this platform over a two-week period, from March 28 to April 12, 2026. During this half-month window, the attacker downloaded a massive volume of documents related to numerous corporate clients.
What client information was stolen?
According to reports, the leaked support tickets frequently had client tax documents attached. Consequently, the exposed data ranges from basic personally identifiable information (PII) such as names, addresses, and Social Security numbers, to deeply sensitive financial details like bank account numbers, credit and debit card information, and various datasets used for tax filing.

EY has sent breach notifications to US state regulators, including the Attorneys General of California and Texas. The report confirms that at least 1,366 residents across multiple states were affected. However, given EY's global client base, the actual number of victims is anticipated to be much larger.
EY stated that they have not yet detected any signs of misuse regarding the stolen data and believe that no specific clients were individually targeted. To mitigate the aftermath, the company is offering two years of free credit monitoring and identity restoration services to affected individuals.
ShinyHunters and the dangerous indirect attack tactic
Before ShinyHunters stepped forward this week, the culprit's identity remained an enigma, and EY had not clarified how the hackers bypassed the third party's security perimeter. The situation shifted when EY's name appeared on ShinyHunters' victim list, alongside other entities like RingCentral and Brinks Home. The group claimed responsibility for a supply chain attack - meaning an indirect assault via EY's service provider partner - to harvest access credentials to the firm's internal systems.
A July 27, 2026 update on the group's website issued a warning: "This is the final reminder to contact us before July 31, 2026, before the data is leaked, along with a few issues that will ensue if EY continues to ignore us."
This tactic mirrors the playbook that ShinyHunters successfully deployed in recent campaigns targeting Instructure, Charter Communications, and McGraw Hill. In prior incidents, the group specialized in exploiting vulnerabilities in Software-as-a-Service (SaaS) platforms, Single Sign-On (SSO) credentials, or utilizing vishing (voice phishing) to exfiltrate massive volumes of data for ransom.
ShinyHunters has become one of the most active extortion groups in 2026. Instead of seeking direct intrusion into the target's network, they choose to exploit vulnerabilities in third parties and the supply chain. The group's recent victims include Instructure's Canvas learning management system (affecting 275 million people) and Charter Communications (40 million records stolen via Microsoft Entra accounts and a hijacked Salesforce instance).
Cybersecurity experts also point out that ShinyHunters is closely linked to the group known as "Scattered Lapsus$ Hunters" - an organization that previously claimed responsibility for attacks on enterprises like Abbott Laboratories using similar vishing tactics and SaaS platform exploitation.
Current status and next developments
To date, the auditing firm EY has remained silent regarding ShinyHunters' claims and has not issued any public response regarding the July 31 deadline. On dark web forums, EY's stolen data has not yet been publicly leaked. The incident remains a focal point of attention within the tech community, once again sounding the alarm on the vital importance of supply chain security and cybersecurity for enterprises in the digital era.
From the perspective of IPSIP Vietnam experts
The importance of safeguarding systems against supply chain risks
The severe data leak at EY is a clear demonstration that when hackers cannot breach core defenses, they pivot to target third parties (such as IT service providers and SaaS software) to steal credentials. The fact that the attacker could infiltrate, lurk, and download mass amounts of sensitive tax data over a two-week period without detection exposes a fatal flaw in monitoring capabilities and access management. This imposes an urgent requirement for enterprises: they must protect systems not only from within but also strictly control the entire supply chain.
Proactive protection solutions from IPSIP Vietnam
To counter increasingly sophisticated indirect attack tactics like those used by ShinyHunters, cybersecurity experts at IPSIP Vietnam emphasize that enterprises need to shift from "passive defense" to "proactive monitoring and response."

Distinguished by international-standard capabilities alongside ISO 27001:2022 and SOC 2 Type II certifications, IPSIP provides a comprehensive cybersecurity solution ecosystem to help enterprises build a solid shield:
24/7 Security Operations Center and Network Operations Center (SOC/NOC): Continuously operates and monitors the entire network infrastructure, ensuring early detection of anomalies (such as a third-party account downloading a massive volume of data) and timely response. Had a robust monitoring system been in place, a two-week blind spot like the EY incident could completely have been prevented early on.
Privileged Access Management (PAM/BASTION): Ensures strict identity control and authorization for all accounts, especially IT support staff or third-party partners. This solution helps grant just-in-time and controlled access rights, minimizing risks from compromised Single Sign-On (SSO) credentials or vishing attacks.
Penetration Testing (Pentest) & Vulnerability Scanning: Periodically reviews and deeply evaluates the security posture of internal service platforms to proactively discover and patch security vulnerabilities before extortion groups target them.
FlexSecure360 comprehensive security solution: A solution package flexibly tailored for every enterprise size (especially SMEs), helping establish a resilient security architecture from endpoints to the cloud at optimized costs.
With a team of battle-tested experts possessing world-leading technology certifications, IPSIP Vietnam not only provides solutions but also acts as a dedicated strategic partner, accompanying enterprises to neutralize every cybersecurity challenge and fully protect digital assets.










Comments