← Ernst & Young LLP

2026 Ernst & Young LLP — third-party IT support platform breach (tax docs); ShinyHunters claim (unverified)

2026 Unknown records affected Share on X

Data compromised

Personal and financial information contained in or used to prepare client tax filings (specific data elements vary by recipient; sample CA notice uses placeholders); investment-holdings context for institutional clients

Technical writeup

Ernst & Young LLP notified affected individuals and filed California AG sample notice materials after detecting anomalous activity on April 23, 2026 in a third-party IT service-management platform used by EY IT personnel supporting tax-related client work. Investigation with an independent cybersecurity firm determined an unauthorized party accessed the platform between March 28 and April 12, 2026 and downloaded documents pertaining to a number of EY clients. Support tickets often included attachments with client tax information. EY stated systems were secured, federal law enforcement was notified, and it was not aware of misuse or targeting of specific individuals; complimentary 24-month Experian IdentityWorks monitoring was offered with enrollment by October 31, 2026. EY has not published an aggregate victim count. On or about July 27, 2026, ShinyHunters added Ernst & Young to its data leak site, claiming responsibility, threatening release unless contacted by July 31, 2026, and telling BleepingComputer that EY credentials were obtained through a supply-chain attack allegedly enabling access to Jira, GitHub, and Azure — EY had not confirmed ShinyHunters attribution or the broader environment claims in sources reviewed. Separate from the October 2025 ~4TB Azure SQL backup exposure involving EY Italy.

Root cause

Unauthorized access to a third-party IT service-management / support-ticket platform used by EY IT staff supporting tax teams; documents attached to tickets were downloaded. ShinyHunters later claimed responsibility via leak-site listing and alleged broader supply-chain credential theft — attribution unverified by EY.

References