AI Stories on SHORT INFO are generated & curated with AI
unverified 30 Jul, 20:10

EY faces July 31 deadline after ShinyHunters data breach claim

The extortion group ShinyHunters added Ernst & Young to its dark web leak site, threatening to publish stolen data if the company does not respond by July 31, 2026. EY has said it detected unauthorized access earlier this year in a third-party platform used for tax related client

The extortion group ShinyHunters added professional services firm Ernst & Young to its dark web leak site on July 27, 2026, with the message "Yes it was us. Now come talk to us," and set a deadline of July 31 before it says it will publish stolen files. EY has said it first detected unusual activity on April 23 inside a third-party IT service management platform its staff use to support tax related client work, and that an investigation found unauthorized access to the platform between March 28 and April 12, during which documents tied to EY clients were downloaded. ShinyHunters claims it obtained EY credentials through a supply chain compromise that gave it access to the company's Jira, GitHub and Microsoft Azure environments. EY has not confirmed that ShinyHunters is behind the incident. Potentially exposed data includes names, home addresses, Social Security numbers, financial account details and payment card data tied to tax filings. Source: BleepingComputer, SecurityAffairs.

#cyber
Published on
YouTubeBlueskyX