ShinyHunters Says It Breached EY Through a Support Ticket System, Not EY Itself
Cybersecurity

ShinyHunters Says It Breached EY Through a Support Ticket System, Not EY Itself

The extortion group behind a wave of Salesforce and SaaS breaches claims it pulled tax documents from a third-party platform EY's own IT staff used to file support tickets, and it has a track record of following through on leak threats.

PublishedAugust 8, 2026
Read time6 min read
Share

What ShinyHunters claims to have taken

ShinyHunters added Ernst & Young to its Tor-hosted leak site on July 27, 2026, claiming to hold client tax filing data pulled from a third-party service management platform that EY's own IT staff used to handle support tickets. The group says the compromised data includes client names and addresses, Social Security numbers, account and payment card numbers, and tax filing information attached to support requests submitted through that platform. EY is one of the largest tax and audit firms in the world, so even a partial confirmation of the claim carries outsized weight for the clients whose filings may have moved through that system.

According to the group's own timeline, the access window ran from March 28 to April 12, 2026, meaning the intrusion sat undetected or unresolved for roughly three and a half months before the public claim surfaced. EY has not disclosed how many individuals are affected, has not named the third-party vendor publicly, and did not respond to press inquiries about the incident, leaving the scope of the exposure defined almost entirely by the attacker's own account.

The deadline and the message

ShinyHunters gave EY until July 31, 2026 to make contact, posting a message on its leak site that read in part: "Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files." No data samples were published alongside the initial claim, and the group did not specify an exact cutoff time for the deadline.

As of the deadline's passing, no credible public report had confirmed that the promised data dump had actually gone live, and the uncertainty itself is part of the group's leverage. Whether EY paid, negotiated an extension, or simply declined to engage publicly cannot be established from outside the negotiation. What is established is that ShinyHunters has a track record of eventually publishing when demands go unmet, which is precisely why professional services firms treat these deadlines as real rather than performative.

Not an isolated target

EY was not the only name ShinyHunters posted that week. The group added RingCentral and Brinks Home, operating as BH Security LLC, to the same leak site within days, each with its own deadline. The Brinks Home claim alleged more than 4.9 million Salesforce records containing personally identifiable information, while the RingCentral claim was vaguer, stating only that an unspecified volume of company data had been compromised without independent verification.

This is consistent with a group Microsoft has separately linked to a year-long campaign against Salesforce-connected environments across dozens of organizations, using compromised support integrations and OAuth tokens rather than direct application exploits. ShinyHunters has previously been tied to breaches at the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and Oracle PeopleSoft customers, a client list that spans healthcare, hospitality, retail, and higher education, not a single industry vertical.

Why the attack vector matters more than the headline

The detail that should worry other Big Four firms and large professional services organizations is the attack vector itself. The claimed entry point was a third-party support ticket system used internally by EY's own IT staff, a tool that almost certainly sat outside the firm's client-facing security reviews because it was purchased and operated as internal tooling rather than as a system built to touch regulated client data. Tax documents ended up inside it anyway, attached to routine support requests over weeks, invisible to whatever controls governed EY's actual client-facing platforms.

That pattern, a low-visibility internal tool accumulating sensitive attachments simply because employees used it for its intended purpose, is one security teams consistently underweight. Support platforms, ticketing systems, and internal collaboration tools rarely appear on a data classification inventory unless someone deliberately audits what gets pasted or attached into them over time. EY's incident is a specific, dated example of that blind spot turning into a seven-figure-record exposure, and it will not be the last firm to discover that its riskiest data lives in a tool nobody thought to classify.

The response playbook, and its limits

EY's public response followed the now-standard breach playbook: engage outside counsel and forensics, decline to comment on attacker attribution or method until confirmed, and offer affected individuals 24 months of free credit monitoring, identity monitoring, and identity restoration services. That response protects individuals from downstream fraud, but it does nothing to prevent the reputational and competitive cost of a Big Four accounting firm having client tax filings sitting on an extortion group's leak site regardless of whether the full archive is ever published.

For CTOs and CISOs at any firm that handles regulated client financial data through outsourced platforms, the EY incident is a reminder to extend data loss prevention and access logging to internal-facing SaaS tools, not just customer-facing ones. An internal support ticket system that accepts file attachments needs the same retention limits, encryption at rest, and periodic content audits as any system explicitly designed to hold client PII, because attackers do not care which category your inventory put it in.

What comes next

Three developments are worth watching closely. Whether ShinyHunters actually publishes verifiable EY client data beyond its initial claim will settle the question of whether this was a real, large-scale breach or an opportunistic extortion attempt riding on a smaller compromise. Whether EY names the third-party vendor publicly will determine how many other firms using the same platform need to check their own exposure. And whether state attorneys general or regulators open inquiries will shape how much this costs EY beyond the credit monitoring bill.

None of those answers change the operational lesson available today. Any firm that has not inventoried what sensitive data lives inside its internal support and ticketing tools, separate from its customer-facing applications, has a gap that looks exactly like the one ShinyHunters says it walked through at EY. That inventory work is unglamorous, rarely funded ahead of an incident, and easy to defer indefinitely when there is no immediate deadline forcing the conversation. It is considerably cheaper than doing it after a leak site has already published the first sample.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#shinyhunters#ernst-young#ey#extortion#third-party-risk#professional-services#tax-data#saas-security