Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ernst & Young hit by network compromise linked to ShinyHunters

Incident
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The Ernst & Young breach involved unauthorized access to a third-party support ticket system and the download of multiple documents, creating exposure risk for client tax data. EY said the attacker entered the platform between March 28 and April 12 and the activity was detected on April 23. The stolen files may contain personal and financial information used for tax filings, and EY says it removed the unauthorized access and notified federal law enforcement. A group calling itself ShinyHunters later claimed responsibility and threatened to publish the data.

Related Happenings

Ernst & Young third-party support ticket data leak involving client tax documents

Data Leak
H score30 First: 17.07.2026 17:55 Last: 17.07.2026 17:55 Sources 1

About this happening: Ernst & Young disclosed a data breach after an unauthorized third party accessed a third-party support ticket system used by its IT personnel and downloaded docume...

Charter Communications hit by network compromise linked to ShinyHunters

Incident
H score70 First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: Charter Communications confirmed a data breach tied to ShinyHunters extortion, with the company saying it is alerting authorities and that no sensitive personal...

Latest development: 29.05.2026 11:29

Have I Been Pwned analyzed leaked Charter Communications data and confirmed that the incident affected 4.9 million accounts, with exposed records including names, email addresses, job titles, phone numbers, and physical addresses. The published data also included a subset of about 85,000 records from an internal employee directory.

7-Eleven hit by network compromise

Incident
H score53 First: 19.05.2026 17:16 Last: 19.05.2026 17:16 Sources 1

About this happening: 7-Eleven is a victim-focused breach incident in which an unauthorized third party accessed systems used to store franchisee documents on April 8, 2026, trigger...

7-Eleven franchisee-docs and Salesforce data leak

Data Leak
H score53 First: 18.05.2026 14:25 Last: 18.05.2026 14:25 Sources 1

About this happening: 7-Eleven confirmed a April 8, 2026 intrusion into systems used to store franchisee documents, and ShinyHunters later claimed the theft of more than 600,000 Sales...

Latest development: 26.05.2026 10:01

Have I Been Pwned analyzed the leaked 7-Eleven data and estimated that the breach exposed personal information for 185,300 people, including names, dates of birth, unique email addresses, phone numbers, and physical addresses. The exposed archive was tied to ShinyHunters' extortion campaign against 7-Eleven and followed the group's leak-site posting after ransom demands were not met.

Over a dozen companies data exposed after SaaS integration provider Snowflake breach

Data Leak
H score69 First: 07.04.2026 22:39 Last: 07.04.2026 22:39 Sources 1

About this happening: A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...

Timeline

  1. 27.07.2026 18:12 1 articles · 2h ago

    Ernst & Young detects unauthorized access to a third-party support ticket system

    Detection Ioc Update

    Ernst & Young detected unusual activity on April 23 and determined that an attacker had accessed a third-party support ticket system used by its IT personnel, downloading multiple documents that may contain client tax information. The company later said it secured its systems, removed the unauthorized access, and notified federal law enforcement.

    Show sources
  2. 27.07.2026 18:12 2 articles · 2h ago

    ShinyHunters claims the Ernst & Young breach and threatens to leak stolen data

    Attribution Update

    The ShinyHunters extortion gang added Ernst & Young to its data leak site, claimed it conducted the attack through stolen credentials obtained in a supply-chain attack, and alleged access to EY's Jira, GitHub, and Azure environments. The group threatened to release the allegedly stolen data unless EY contacted it by July 31, 2026, while saying it would not identify the compromised third party or disclose what data was stolen.

    Show sources