Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days.Learn More
MERENA
Advisory Alert

Ernst & Young data breach claimed by ShinyHunters extortion gang

A criminal group says it broke into some Ernst & Young systems by going through a connected outside provider and may have accessed account sign-in details. This is a warning that people and businesses connected to large service firms can be affected even when the problem starts somewhere else.


Who is at risk

Ernst & Young clients, employees, contractors, and anyone who uses related accounts, shared files, or messages connected to the company may be most at risk.

What to watch for

Watch for unexpected password reset messages, login alerts, requests to approve sign-ins, unusual emails claiming to be from Ernst & Young, or unfamiliar activity in linked accounts.

What to do

Change passwords on any related accounts, turn on two-step sign-in if available, and confirm any unusual message or request by contacting Ernst & Young or your organization through official channels.