Editor’s Note: A ShinyHunters extortion listing against Ernst & Young reached its stated July 31 deadline today, and with it the industry learns whether tax records held by a Big Four firm land on a criminal leak site. The confirmed breach ran through a third-party IT service management platform, where support tickets quietly accumulated documents holding Social Security numbers, account details, and card numbers; how the intruder first got in has not been established publicly.
Cybersecurity teams will read this as a third-party ITSM platform compromise, with supply-chain risk as the interpretive frame rather than an established access route. Information governance professionals will recognize a case study in unmanaged data at rest inside help-desk queues. Legal and eDiscovery teams should note that a proposed class action was filed July 20, before the deadline arrived, and that the discovery fights over vendor-held data are already predictable.
Watch three things next: whether authentic data actually publishes, whether EY names the vendor, and how far the notification cascade spreads beyond the states counted so far.
Content Assessment: ShinyHunters' July 31 deadline for EY arrives after third-party tax-data breach
Information - 92%
Insight - 91%
Relevance - 92%
Objectivity - 91%
Authority - 90%
91%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "ShinyHunters' July 31 deadline for EY arrives after third-party tax-data breach."
Industry News – Cybersecurity Beat
ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
ComplexDiscovery Staff
A self-imposed deadline set by the ShinyHunters extortion group for Ernst & Young arrived Friday, with tax-related client data from a Big Four firm as the claimed bargaining chip.
The group added EY to its leak site July 27 and threatened to release allegedly stolen data unless the firm made contact by July 31. It published no samples, specified no exact cutoff time, and EY has not attributed its disclosed breach to ShinyHunters. As of 10:30 a.m. Eastern time July 31, no credible public report reviewed by ComplexDiscovery had confirmed publication.
The listing lands on a wound EY had already disclosed. In notification letters filed with state attorneys general beginning in mid-July, the firm confirmed that an unauthorized party accessed a third-party information technology service management (ITSM) platform, downloading documents tied to client tax work across a window running from late March into mid-April. Whether the group follows through, and what actually publishes if it does, will shape breach-response, notification, and litigation decisions across EY’s client base for months.

Inside EY’s disclosure
According to the firm’s breach notifications, the intrusion ran from March 28 through April 12, and EY detected anomalous activity April 23. The compromised system was a third-party ITSM platform that EY information technology personnel use to support teams performing tax-related work for clients. Support tickets submitted through the platform can carry attachments, and those attachments can carry client tax documents. How the intruder first got in has not been established publicly.
That design detail is the heart of the story. The exposed material, as described in notifications summarized by SecurityWeek reporter Ionut Arghire, included client names, addresses, Social Security numbers, account numbers, credit and debit card numbers, and other information used for tax filings. EY has not named the vendor, has not disclosed a total victim count, and said it has found no evidence the data has been misused. The firm reported the incident to federal law enforcement, engaged an outside cybersecurity firm, and is offering affected individuals 24 months of identity monitoring and restoration services through Experian, with enrollment open through Oct. 31, 2026.
State filings provide partial, jurisdiction-specific counts. Public notifications identify 873 affected Texans, 480 Massachusetts residents, and 13 Vermont residents. California does not publish a count, but its attorney general posts sample notices only when a business notifies over 500 California residents, placing the four-state minimum above 1,866. EY has not disclosed a total, state filings capture only residents of states that publish notifications, and the full affected population is likely far larger. As of July 31, EY has not published a global tally.
Claims that remain unverified
ShinyHunters’ leak-site listing, first reported July 27 by BleepingComputer’s Lawrence Abrams, went further than EY’s disclosure. The group claimed it obtained EY credentials through a supply-chain compromise and asserted access to the firm’s Jira, GitHub, and Microsoft Azure environments. It declined to name the compromised third party, did not publish samples, and did not specify what it took.
None of those added claims has been verified, and EY has not confirmed that ShinyHunters was the actor behind the intrusion it disclosed. That gap matters. Extortion groups routinely inflate access claims to raise pressure during a negotiation window, and confirmation of source-code or cloud-environment access would materially expand the incident’s known scope. Readers should treat the Jira, GitHub, and Azure claims as allegations unless independently corroborated; even leaked data might authenticate possession without establishing the claimed access route.
Who is making the threat
The ShinyHunters name has circulated since 2020, but researchers caution against treating it as a single stable organization. Google’s threat intelligence unit tracked 2025 voice-phishing intrusions targeting Salesforce environments as UNC6040 and the ShinyHunters-branded extortion that followed as UNC6240, while a separate campaign reached Salesforce instances through stolen Salesloft Drift OAuth tokens as UNC6395; actors involved claimed about 1 billion records across the Salesforce-related activity.
The label, in other words, is a brand as much as a roster. In January the unit said it follows ShinyHunters-branded operations as several distinct clusters to account for shifting partnerships and possible impersonation. The branding has also appeared jointly with actors claiming ties to Scattered Spider and Lapsus$ under the banner Scattered Lapsus$ Hunters, and U.S. and French authorities seized the BreachForums clearnet domain associated with the group in October 2025, though its Tor site stayed online.
Researchers who track the activity counsel against engaging it. Allison Nixon, chief research officer at the security research firm Unit 221B, told the reporter Brian Krebs in February that the group makes commitments to victims it does not intend to honor, and that refusing to negotiate is the sound strategy because stolen data cannot be bought back in any verifiable way. Nixon’s analysis carries a warning for the press as well: public attention is part of the pressure campaign, a dynamic any coverage of an extortion listing, this article included, has to weigh.
EY, for its part, arrives at this moment with history. The firm was among the many organizations swept up in the 2023 MOVEit Transfer exploitation, and in October 2025 researchers at Neo Security reported finding a 4-terabyte EY SQL Server backup publicly exposed on Azure. EY said that exposure was remediated immediately, was localized to an entity acquired by EY Italy, and affected no client, personal, or confidential EY data. The three events differ in character and severity, but plaintiffs and regulators tend to present such sequences as a pattern, and EY should expect exactly that argument.
Litigation is already moving
Plaintiffs did not wait for the deadline. Illinois resident Markishi Wyatt filed a proposed class action against Ernst & Young LLP on July 20 in the U.S. District Court for the Southern District of New York, case number 1:26-cv-06108, alleging the firm failed to protect the tax and financial information entrusted to it and estimating the affected class in the tens or hundreds of thousands, according to the docket and reporting by CFO Dive and Law360. Plaintiffs’ firms, including Edelson Lechtzin, have announced investigations seeking affected clients; those announcements are client-acquisition marketing as well as legal analysis and should be read as both.
If authentic data linked to affected individuals are published, plaintiffs may argue the release strengthens allegations of dissemination and concrete injury; whether it does turns on what is published and whether it can be tied to real people. Preservation and notification duties are equally fact-specific. A litigation-hold obligation attaches when litigation is reasonably anticipated, not automatically upon appearing in an affected population, and notification duties generally arise from the discovery or determination of unauthorized access or acquisition, depending on applicable law, rather than from a later extortion deadline or criminal publication. The discovery posture is still predictable: the ITSM platform, EY’s incident-response records, and the contracts governing the two will be early targets, and data held on a third party’s system raises familiar possession, custody, and control questions from the first preservation letter.
What this asks of practitioners
For cybersecurity, information governance, and eDiscovery professionals, the instructive failure is unglamorous: a help-desk ticket queue became a repository of regulated data. ITSM platforms can be overlooked in data inventories, yet any attachment retained on a support ticket becomes data at rest on a third party’s system. Inventory those platforms, restrict what ticket workflows can accept as attachments, and set retention on closed tickets so resolved requests stop accumulating tax documents. Review vendor contracts for breach-notification timelines and audit rights before an incident makes the gaps visible. And if your organization is an EY tax client, the immediate work is narrower: confirm whether your data sits in the affected population, assess with counsel the notification duties already raised by the confirmed access, decide whether litigation is reasonably anticipated and preservation is warranted, and revisit risk-of-harm and supplemental-notice analyses if publication occurs.
After the deadline arrives
Publicly visible outcomes can include publication, an extended or removed deadline, or no immediate action, and none of those, standing alone, establishes whether the underlying claim was accurate or whether payment occurred. The Salesforce campaign offers the closest recent sequence: Salesforce said it would not pay, U.S. and French authorities seized the BreachForums clearnet domain shortly before the group’s announced publication time, and the group continued operating from its Tor site. Payment, as Nixon’s research group argues, buys no verifiable deletion. However this listing resolves, the underlying lesson is already fixed, because the professional-services supply chain has become the soft route to hard targets, and firms whose product is confidentiality are learning that their vendors’ security is their own. Whatever follows the deadline, will the industry treat it as EY’s problem, or as a preview of its own?

News sources
- Ernst & Young data breach claimed by ShinyHunters extortion gang (BleepingComputer)
- Ernst & Young discloses data breach after support system hack (BleepingComputer)
- Ernst & Young data breach affects personal, financial information (SecurityWeek)
- ShinyHunters claims Ernst & Young hack (SecurityWeek)
- EY hit with proposed class action over data breach (CFO Dive)
- Wyatt v. Ernst & Young LLP, No. 1:26-cv-06108 (S.D.N.Y.) (Justia Dockets)
- Submitted breach notification sample: Ernst & Young LLP (California Office of the Attorney General)
- The cost of a call: from voice phishing to data extortion (Google Cloud Threat Intelligence)
- Expansion of ShinyHunters-linked SaaS data theft (Google Cloud Threat Intelligence)
- EY subject of 4TB data exposure following cloud migration error (SDxCentral)
- FBI takes down BreachForums portal used for Salesforce extortion (BleepingComputer)
- Please don’t feed the Scattered Lapsus$ Hunters (KrebsOnSecurity)
Assisted by GAI and LLM technologies
Additional reading
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
- Stadler rejects $12.3 million ransom after supplier-linked platform breach
- SharePoint attackers are stealing the keys, and patching alone will not evict them
- UK and EU impose first simultaneous cyber sanctions as Poland attack is attributed to the FSB
- The negotiator was the leak: insider who betrayed ransomware victims gets 70 months
- Why a single Signal recovery key is a preservation problem
- Europe’s critical sectors are maturing, but seven still sit in ENISA’s risk zone
- When the worm targets the assistant: Miasma turns AI coding agents into the trigger
- Glasswing widens: Anthropic puts Mythos inside power, water and hospital operators across more than 15 countries
- Canvas breach moves from disclosure to demand as ShinyHunters sets May 12 deadline
- CISA’s CI Fortify rewrites the disconnection playbook for critical infrastructure
- A 48-month federal benchmark resets the incident-response insider question
- Data collection in occupied territory: A closer read of Cyber Law Toolkit scenario 35
- Cyber Law Toolkit tests surveillance and data collection under occupation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.


























