ShinyHunters set a July 31 deadline on Ernst and Young: what organizations need to know
ShinyHunters posted a final warning on its dark web leak site on July 28, 2026, claiming a breach of Ernst and Young via a third-party IT service management platform. The group set a July 31 publication deadline. Ernst and Young has confirmed the breach independently: an unauthorized third party accessed a support ITSM platform from March 28 to April 12, 2026.
What was accessed
EY's disclosure describes the breached system as a third-party ITSM platform used by EY's IT staff to provide support for tax-related client work. Support tickets submitted through the platform may include documents containing client personal and financial information from tax filings. ShinyHunters claims it used credentials stolen from the ITSM platform to reach EY's Jira, GitHub, and Azure environments. EY has not confirmed or denied the broader environment access claim.
Why this is a supply chain story
The entry point was not EY itself. It was a third-party IT service management platform that EY used for internal support workflows. The attacker gained access to EY client data not by breaching EY's own systems directly, but by compromising the software vendor EY used to manage its IT help desk tickets. This is the same attack pattern ShinyHunters used against Oracle PeopleSoft earlier this year: breach the third-party platform, harvest credentials or data from clients at scale.
For organizations that use EY as external auditor, tax advisor, or management consultant: the question to answer is whether your engagement with EY involved documents or data submitted through their IT support infrastructure between March 28 and April 12, 2026. That is the window during which the unauthorized access ran. If your team submitted sensitive documents or credentials through EY's IT support channels during that period, start your assessment now.
What the July 31 deadline means
ShinyHunters operates a double-extortion model: exfiltrate data, demand payment, set a public deadline, then either leak or continue negotiations. The July 31 deadline does not necessarily mean data will be published on August 1. These deadlines frequently extend. But the extortion campaign also confirms that ShinyHunters believes it has data worth publishing. EY has not announced it will pay and has not publicly responded to the deadline.
Watch for EY client notifications in the next 24 to 48 hours. If ShinyHunters leaks and the data set is as broad as claimed, downstream notifications to individuals and organizations whose tax data was in the support platform will follow.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help assessing your exposure or responding to the EY incident.