Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 3 sources · 15 days · First seen · Last updated
Categories: CRIME · TECHNOLOGY
ShinyHunters cyber extortion campaign
Entities: ShinyHunters hacking group · Ernst & Young · ADT · Ernst & Young (EY) · McGraw Hill
Overview
In July 2026, the ShinyHunters extortion group was reported to be exploiting stale credentials to infiltrate education and corporate networks, compromising data across multiple sectors.
Two weeks later, investigators linked the group to a supply‑chain breach of Ernst & Young (EY) that exposed client tax documents and personal information of more than 1,300 U.S. residents. The attackers also leveraged email addresses harvested from the breach to launch a Bitcoin‑based sextortion scheme, threatening victims with fabricated webcam recordings. ShinyHunters denied involvement in the sextortion emails, but the campaign repurposed data from prior breaches of firms such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 2 SOURCES] ShinyHunters leaked email addresses from breaches at Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. (ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
- [● 2 SOURCES] Scammers are sending sextortion emails demanding $2,000 in Bitcoin, claiming to have recorded victims, and using leaked email addresses to appear credible. (ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
- [● 2 SOURCES] Scammers are using email addresses leaked by ShinyHunters to send sextortion emails demanding $2,000 in Bitcoin. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
- [● 2 SOURCES] The sextortion campaign leverages data from breaches of Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread and McGraw Hill. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
- [○ 1 SOURCE] ShinyHunters claimed responsibility for the Ernst & Young data breach. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] The EY breach involved a supply‑chain compromise of a third‑party IT support platform. (9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] EY disclosed the breach after detecting anomalous activity on April 23, 2026. (9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] At least 1,366 U.S. residents were affected by the EY breach. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] EY is offering two years of free credit monitoring and identity restoration services to affected individuals. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] ShinyHunters denied involvement in the sextortion email campaign. (article ba7b6bd9-858f-4f1e-9c9a-ace52c8f5c6c)
- [○ 1 SOURCE] Unauthorized access to a third‑party IT service platform occurred from March 28 to April 12 2026. (article 9d9a3d55-b9ab-42b4-bef9-91bc4f8e245f)
- [○ 1 SOURCE] The sextortion emails falsely claim victims were recorded via webcam and threaten to publish the footage. (article 6158631d-82a2-43c2-9273-6cf310e9cb72)
Timeline
-
2 days ago
[CRIME] 3 sourcesShinyHunters data leaks drive Bitcoin sextortion scam and EY breachShinyHunters claimed the EY breach exposing client data, while its leaked email lists are being used in Bitcoin‑demanding sextortion scams targeting victims of multiple company breaches.
-
17 days ago
[TECHNOLOGY] 2 sourcesShinyHunters exploits stale credentials to breach education and corporate data in 2026Stale credentials and vishing enabled ShinyHunters and others to breach Instructure, Charter, Carnival and other firms, exposing data of tens of millions in 2026.
Sources
europesays.com · invitehealth.substack.com · malwarebytes.org