Data breach
Ernst & Young
- Records
- 1,205,607
- Breach date
- 27 July 2026Estimated
- Added
- 7 October 2026
What was exposed
12 types of data · 1 more reported · 4 put you at serious risk
- Email addresses1,205,607
- Phone numbers704,241
- Names394,042
- Street addresses236,825
- Dates of birth65,445
- Social security numbers11,611
- Medical diagnoses79
- Passport numbers36
- Licence plates26
- Driving licence numbers25
- Bank account numbers19
- Vehicle VINs4
- Card numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Ernst & Young (EY), one of the four largest professional services firms in the world, disclosed a data breach in which an unauthorized party accessed a third-party IT support platform used by the firm's tax teams and downloaded documents belonging to multiple clients. In mid-July 2026, the ShinyHunters extortion group claimed responsibility for the intrusion and threatened to publish the stolen data unless the firm negotiated by July 31, 2026. EY has not confirmed that ShinyHunters was behind the attack. The investigation team has indexed about 1.2 million records linked to this listing.
March 28 to April 12, 2026: According to EY's breach notifications, an unauthorized party accessed a third-party IT service management platform during this window and downloaded client documents.
April 23, 2026: EY detected unusual activity on the platform.
Mid-July 2026: EY disclosed the breach and filed notification letters with state attorneys general, including California and Texas.
July 20, 2026: An Illinois resident filed a proposed class action against Ernst & Young LLP in the U.S. District Court for the Southern District of New York.
July 27, 2026: ShinyHunters added EY to its dark web leak site, claiming it obtained credentials through a supply-chain compromise, according to BleepingComputer.
July 31, 2026: The group's stated deadline for EY to make contact passed and the data was published.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses, 1,205,607 records
Phone numbers, 704,241 records
Names, 394,042 records
Street addresses, 236,825 records
Dates of birth, 65,445 records
Social Security numbers, 11,611 records
EY's notifications to state attorneys general stated that the downloaded support tickets could contain attachments with client tax documents, including names, home addresses, Social Security numbers, financial account details, and payment card data used in tax filings. The firm has not named the compromised vendor, disclosed a total victim count, or confirmed the full scope of the data taken.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with names, addresses, and dates of birth can support identity theft and fraudulent tax filings in someone else's name. Tax and financial details also give criminals material for convincing phishing messages that impersonate EY, the IRS, or state tax agencies, since the sender can reference real personal information to appear legitimate. Exposed financial account and payment card numbers raise the risk of direct fraud. If ShinyHunters publishes the files it claims to hold, this information would become permanently available to other criminals. Anyone whose data appears in this breach should treat unexpected emails, calls, or texts about taxes or EY services with suspicion, even when they reference accurate personal details.
What Is Ernst & Young Doing in Response?
EY has said it secured its systems, removed the unauthorized access, reported the incident to federal law enforcement, and engaged an outside cybersecurity firm. The firm stated it found no evidence the data has been misused and does not believe the incident targeted a specific client. It is offering affected individuals 24 months of identity monitoring and restoration services through Experian, with enrollment open through October 31, 2026, according to Cybernews. State filings identified 873 affected Texas residents, 480 Massachusetts residents, and 13 Vermont residents, figures that represent only a minimum. The ShinyHunters claims about accessing EY's internal systems remain unverified.
What Should You Do If You Were Affected?
Enroll in the credit monitoring EY is offering if you received a notification letter. Check your credit reports at annualcreditreport.com for accounts you do not recognize. Consider a credit freeze or fraud alert with the three major bureaus. Request an IRS Identity Protection PIN to block fraudulent tax returns filed in your name. Monitor bank and card statements for unfamiliar charges, and be cautious with any message claiming to come from EY or a tax agency.
In the news
- BleepingComputer: Ernst & Young data breach claimed by ShinyHunters extortion gangbleepingcomputer.com (opens in a new tab)
- Cybernews: ShinyHunters claims EY breach, warns all stolen data will be releasedcybernews.com (opens in a new tab)
- ComplexDiscovery: ShinyHunters' July 31 deadline for EY arrives after third-party tax data breachcomplexdiscovery.com (opens in a new tab)
- GBHackers: ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Datagbhackers.com (opens in a new tab)
