ERNST & YOUNG LLP
bd_dd03905a2bb4d77f · schema v1 · pii pii-v1
Full breach record for ERNST & YOUNG LLP →5 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shinyhunters on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files. This is a final warning to reach out by 31 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 27 July 2026 | Warning: FINAL WARNING PAY OR LEAK
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jul 27, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Texas State AGbd_fd00b5fb305eb1e22026-07-17 · +10dVerified
- Vermont State AGbd_e6037bfd1b169e8c2026-07-16 · +11dVerified
- Massachusetts State AGbd_0d2e166fcb18c8cf2026-07-15 · +12dVerified
- New Hampshire State AGbd_29b6b4794ab7836c2026-07-15 · +12dVerified
Show 2 more filings ↓Show fewer ↑up to 13d gap
- California State AGbd_42c010b106cfcaeb2026-07-15 · +12dVerified
- Nebraska State AGbd_f6da314010d1a4dd2026-07-14 · +13dCandidate
Filing propagation · 7 filings · 6 states
View merged incident ↗Pattern: first filing Jul 14 (NE), last Jul 27 — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shinyhunters
According to ransomware.live, ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.