Ernst & Young hit by network compromise linked to ShinyHunters
Incident
Summary
Hide ▲
Show ▼
The Ernst & Young breach involved unauthorized access to a third-party support ticket system and the download of multiple documents, creating exposure risk for client tax data. EY said the attacker entered the platform between March 28 and April 12 and the activity was detected on April 23. The stolen files may contain personal and financial information used for tax filings, and EY says it removed the unauthorized access and notified federal law enforcement. A group calling itself ShinyHunters later claimed responsibility and threatened to publish the data.
Related Happenings
Ernst & Young third-party support ticket data leak involving client tax documents
Data Leak
H score30
First: 17.07.2026 17:55
Last: 17.07.2026 17:55
Sources 1
About this happening:
Ernst & Young disclosed a data breach after an unauthorized third party accessed a third-party support ticket system used by its IT personnel and downloaded docume...
Ernst & Young third-party support ticket data leak involving client tax documents
Data LeakAbout this happening: Ernst & Young disclosed a data breach after an unauthorized third party accessed a third-party support ticket system used by its IT personnel and downloaded docume...
Charter Communications hit by network compromise linked to ShinyHunters
Incident
H score70
First: 26.05.2026 22:46
Last: 26.05.2026 22:46
Sources 1
About this happening:
Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...
Charter Communications hit by network compromise linked to ShinyHunters
IncidentAbout this happening: Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...
Latest development: 29.05.2026 11:29
Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.
7-Eleven hit by network compromise
Incident
H score53
First: 19.05.2026 17:16
Last: 19.05.2026 17:16
Sources 1
About this happening:
7-Eleven is a victim-focused breach incident in which an unauthorized third party accessed systems used to store franchisee documents on April 8, 2026, trigger...
7-Eleven hit by network compromise
IncidentAbout this happening: 7-Eleven is a victim-focused breach incident in which an unauthorized third party accessed systems used to store franchisee documents on April 8, 2026, trigger...
7-Eleven franchisee-docs and Salesforce data leak
Data Leak
H score53
First: 18.05.2026 14:25
Last: 18.05.2026 14:25
Sources 1
About this happening:
7-Eleven confirmed a April 8, 2026 intrusion into systems used to store franchisee documents, and ShinyHunters later claimed the theft of more than 600,000 Sales...
7-Eleven franchisee-docs and Salesforce data leak
Data LeakAbout this happening: 7-Eleven confirmed a April 8, 2026 intrusion into systems used to store franchisee documents, and ShinyHunters later claimed the theft of more than 600,000 Sales...
Latest development: 26.05.2026 10:01
Have I Been Pwned analyzed the leaked 7-Eleven data and estimated that the breach exposed personal information for 185,300 people, including names, dates of birth, unique email addresses, phone numbers, and physical addresses. The exposed archive was tied to ShinyHunters' extortion campaign against 7-Eleven and followed the group's leak-site posting after ransom demands were not met.
Over a dozen companies data exposed after SaaS integration provider Snowflake breach
Data Leak
H score69
First: 07.04.2026 22:39
Last: 07.04.2026 22:39
Sources 1
About this happening:
A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...
Over a dozen companies data exposed after SaaS integration provider Snowflake breach
Data LeakAbout this happening: A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...
Timeline
-
27.07.2026 18:12 1 articles · 2h ago
Ernst & Young detects unauthorized access to a third-party support ticket system
Detection Ioc UpdateErnst & Young detected unusual activity on April 23 and determined that an attacker had accessed a third-party support ticket system used by its IT personnel, downloading multiple documents that may contain client tax information. The company later said it secured its systems, removed the unauthorized access, and notified federal law enforcement.
Show sources
- Ernst & Young data breach claimed by ShinyHunters extortion gang — www.bleepingcomputer.com — 27.07.2026 18:12
-
27.07.2026 18:12 2 articles · 2h ago
ShinyHunters claims the Ernst & Young breach and threatens to leak stolen data
Attribution UpdateThe ShinyHunters extortion gang added Ernst & Young to its data leak site, claimed it conducted the attack through stolen credentials obtained in a supply-chain attack, and alleged access to EY's Jira, GitHub, and Azure environments. The group threatened to release the allegedly stolen data unless EY contacted it by July 31, 2026, while saying it would not identify the compromised third party or disclose what data was stolen.
Show sources
- Ernst & Young data breach claimed by ShinyHunters extortion gang — www.bleepingcomputer.com — 27.07.2026 18:12
- Ernst & Young data breach claimed by ShinyHunters extortion gang — www.bleepingcomputer.com — 27.07.2026 18:12