The record
Written from the 2 reports below. Nothing here is unsourced.
- ShinyHunters, a prolific data extortion group, claims responsibility for a data breach at Ernst & Young, exploiting a third-party support ticket system in what appears to be a supply-chain attack.
- The threat actors say they obtained database dumps from multiple major companies including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill.
- The breach also enables secondary extortion tactics—attackers are using exposed email addresses from these leaks to send sextortion emails demanding $2,000 in Bitcoin.
- While Ernst & Young has not publicly confirmed the breach, the list of affected companies spans retail, financial services, media, and consumer sectors.
- The incident highlights ongoing risks from third-party vendors and support systems that may have weaker security controls than primary infrastructure.
- Users whose emails may have been exposed should delete suspicious extortion emails, avoid replying, and contact their financial institutions if concerned about fraud.
- Organizations should review third-party access controls and incident response procedures in light of this supply-chain vector.
What to watch next
- Monitor for confirmation from EY on breach scope
- Check if your organization used affected third-party vendors
- Watch for sextortion emails using leaked credentials
- Review third-party support system access controls
What changed2
Every report on this story, newest first. Times are when each outlet published.
BleepingComputer[1]
Ernst & Young data breach claimed by ShinyHunters extortion gangBleepingComputer[2]
ShinyHunters data leaks fuel $2,000 sextortion email scam
Why it matters10
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Ernst & Young data breach via supply chain· immediate
- Amtrak database exposed· immediate
- Hallmark database exposed· immediate
- Substack database exposed· immediate
- Betterment database exposed· immediate
- CarGurus database exposed· immediate
- ADT database exposed· immediate
- Panera Bread database exposed· immediate
- McGraw Hill database exposed· immediate
- Email account holders extortion email campaign· immediate
Coverage1
All filed from United StatesSingle origin
Named United States · ADT · Amtrak · Betterment · CarGurus · Ernst & Young · Experian · Hallmark · McGraw Hill · Panera Bread · Substack · ShinyHunters
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

