< Back to all clusters
[CRIME] · United States · 3 sources

ShinyHunters data leaks drive Bitcoin sextortion scam and EY breach

The ShinyHunters extortion group claimed responsibility for a supply‑chain breach of Ernst & Young (EY) that gave attackers access to a third‑party IT service platform from March 28 to April 12 2026. EY reported that the intrusion exposed client tax documents and personal data of at least 1,366 U.S. residents, and the firm is offering two years of free credit monitoring and identity restoration.

Separately, scammers are exploiting email addresses leaked by ShinyHunters to send sextortion messages demanding $2,000 in Bitcoin. The emails falsely claim the victims were recorded via webcam and threaten to publish the footage. The campaign reuses data from breaches of companies such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. ShinyHunters has denied involvement in the sextortion emails.

Entities: ADT · Amtrak · Ernst & Young · Ernst & Young (EY) · Hallmark · McGraw Hill · ShinyHunters · ShinyHunters hacking group

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] EY disclosed the breach after detecting anomalous activity on April 23, 2026. (9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
  • [○ 1 SOURCE] The EY breach involved a supply‑chain compromise of a third‑party IT support platform. (9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
  • [○ 1 SOURCE] ShinyHunters claimed responsibility for the Ernst & Young data breach. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
  • [● 2 SOURCES] ShinyHunters leaked email addresses from breaches at Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. (ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
  • [○ 1 SOURCE] EY is offering two years of free credit monitoring and identity restoration services to affected individuals. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
  • [● 2 SOURCES] Scammers are sending sextortion emails demanding $2,000 in Bitcoin, claiming to have recorded victims, and using leaked email addresses to appear credible. (ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
  • [○ 1 SOURCE] ShinyHunters denied involvement in the sextortion email campaign. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
  • [○ 1 SOURCE] At least 1,366 U.S. residents were affected by the EY breach. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
  • [● 2 SOURCES] The sextortion campaign leverages data from breaches of Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
  • [○ 1 SOURCE] The sextortion emails falsely claim victims were recorded via webcam and threaten to publish the footage. (article 6158631d-82a2-43c2-9273-6cf310e9cb72)
  • [● 2 SOURCES] Scammers are using email addresses leaked by ShinyHunters to send sextortion emails demanding $2,000 in Bitcoin. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
  • [○ 1 SOURCE] Unauthorized access to a third‑party IT service platform occurred from March 28 to April 12 2026. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)