< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 3 sources · 15 days · First seen · Last updated

Categories: CRIME · TECHNOLOGY

ShinyHunters cyber extortion campaign

Entities: ShinyHunters hacking group · Ernst & Young · ADT · Ernst & Young (EY) · McGraw Hill

Overview

In July 2026, the ShinyHunters extortion group was reported to be exploiting stale credentials to infiltrate education and corporate networks, compromising data across multiple sectors.

Two weeks later, investigators linked the group to a supply‑chain breach of Ernst & Young (EY) that exposed client tax documents and personal information of more than 1,300 U.S. residents. The attackers also leveraged email addresses harvested from the breach to launch a Bitcoin‑based sextortion scheme, threatening victims with fabricated webcam recordings. ShinyHunters denied involvement in the sextortion emails, but the campaign repurposed data from prior breaches of firms such as Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 2 days ago

    [CRIME] 3 sources
    ShinyHunters data leaks drive Bitcoin sextortion scam and EY breach

    ShinyHunters claimed the EY breach exposing client data, while its leaked email lists are being used in Bitcoin‑demanding sextortion scams targeting victims of multiple company breaches.

  2. 17 days ago

    [TECHNOLOGY] 2 sources
    ShinyHunters exploits stale credentials to breach education and corporate data in 2026

    Stale credentials and vishing enabled ShinyHunters and others to breach Instructure, Charter, Carnival and other firms, exposing data of tens of millions in 2026.

Sources

europesays.com · invitehealth.substack.com · malwarebytes.org