Back to Blog
Ernst & Young Ransomware: Client and Tax Data Exposed in Coordinated July 2026 Attacks
ransomware

Ernst & Young Ransomware: Client and Tax Data Exposed in Coordinated July 2026 Attacks

breachwire TeamAug 27, 20265 min read

Ernst & Young: What Happened

In July 2026, Ernst & Young (EY) was targeted by a ransomware attack orchestrated by the ShinyHunters group. The incident resulted in the confirmed exposure of sensitive client information and tax records, with the attackers claiming access to a significant volume of confidential data. Concurrently, Fairlife, a subsidiary of Coca-Cola, experienced a separate ransomware attack attributed to the Anubis group, which asserted the theft of over 1TB of data. Both incidents occurred in North America and were part of a broader surge in ransomware activity during the month.

Attack Vector & Technical Detail

While the specific initial access vector for the Ernst & Young breach has not been publicly disclosed, the tactics align with known ShinyHunters methodologies, which often leverage phishing, credential compromise, and exploitation of unpatched systems. No CVEs or IOCs have been formally attributed to this incident in the available reporting. The MITRE tactics likely involved Initial Access (TA0001), Credential Access (TA0006), and Exfiltration (TA0010), consistent with the observed data theft and extortion patterns. For Fairlife, the Anubis group’s claim of exfiltrating over 1TB of data suggests a prolonged dwell time and substantial lateral movement within the target environment.

Confirmed Impact

The breach at Ernst & Young led to the exposure of sensitive client and tax data, raising significant concerns regarding regulatory compliance and client confidentiality in the North American region. For Fairlife, the theft of over 1TB of data by the Anubis group represents a substantial compromise of proprietary and potentially personally identifiable information. Both incidents may trigger mandatory breach notifications under U.S. state and federal data protection laws, as well as potential international regulatory scrutiny given the global footprint of the affected organizations.

What This Means for Your Organization

These incidents underscore the persistent threat posed by ransomware groups targeting professional services and critical supply chain entities. Organizations should prioritize multi-layered defenses against phishing, enforce strong credential management, and ensure timely patching of systems. The absence of disclosed CVEs in this case highlights the importance of behavioral monitoring and rapid detection of anomalous activity, especially in environments handling sensitive client or financial data.

Detection & Response

  • Immediate: Conduct a comprehensive review of access logs and privileged account activity for signs of unauthorized access.
  • Hunt: Monitor for behavioral indicators consistent with ShinyHunters and Anubis group tactics, including unusual data exfiltration patterns and lateral movement.
  • Patch: N/A (no specific CVEs disclosed in this incident).

Source: https://www.zdnet.com/article/ransomware-july-victim-count-spiked-in-july-but-whats-behind-it/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: