The ShinyHunters extortion group has updated its data leak site with three new organizations, issuing what it describes as “final warning” notices to Ernst & Young (EY), RingCentral, and Brinks Home before the alleged publication of stolen data.
The updates, posted on July 27, set deadlines ranging from July 30 to July 31 and warn that the group intends to release the allegedly stolen data if negotiations do not take place. Unlike the other newly listed organizations, EY had already disclosed a cybersecurity incident earlier this month involving a compromised third-party support ticket platform. At the time of publication, RingCentral and Brinks Home had not issued public statements regarding the claims.
ShinyHunters claims responsibility for disclosed EY breach
ShinyHunters claims responsibility for the previously disclosed Ernst & Young incident, stating the company has until July 31 to make contact before the group publishes the purportedly stolen files.
Earlier this month, EY notified affected customers that an unauthorized third party accessed a third-party support ticket system used by its IT personnel between March 28 and April 12. According to the company, the attackers downloaded documents that may have contained personal and financial information used in tax preparation. EY said it secured the affected platform, notified law enforcement, and began offering impacted customers identity monitoring services.
At the time of EY’s disclosure, no ransomware or extortion group had publicly claimed responsibility for the incident. ShinyHunters’ latest leak-site posting appears to be the first public attempt to attribute the breach to the group.
The post reads in part:
“Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files.”
The group also warns of additional “digital problems” if negotiations do not occur before the deadline, although it does not elaborate on what those threats entail.
RingCentral and Brinks Home also listed
RingCentral was simultaneously added to the leak site with a July 30 deadline. ShinyHunters claims to have compromised company data but does not specify the amount of information allegedly stolen, instead stating only that “over XX of data was compromised.”
Brinks Home, listed as BH Security LLC (brinkshome.com), was also added with the same July 30 deadline. In that listing, the group claims to possess more than 4.9 million Salesforce records containing personally identifiable information.
Neither listing was accompanied by publicly available evidence sufficient to independently verify the alleged compromises.
Leak site infrastructure restored
Alongside the new victim listings, ShinyHunters published an operational update regarding its content delivery infrastructure.
According to the notice, all CDN mirrors are back online following a service disruption that began on July 25. The group says content synchronization across its mirrors remains in progress and that it is preparing torrent releases for its leaked datasets. It also encouraged visitors to seed the files once they become available.
While such announcements cannot be independently verified, the update suggests the group is restoring its distribution infrastructure ahead of future data releases.
Pressure campaign continues
The newly published deadlines are consistent with ShinyHunters’ use of public leak sites to pressure organizations into entering negotiations before allegedly stolen data is released.
While EY has acknowledged a breach involving a third-party support platform, it has not publicly attributed the incident to ShinyHunters. RingCentral and Brinks Home had not issued public statements addressing the group’s claims at the time of publication.
BreachNews will continue monitoring the listings for any published evidence, company responses, or data releases.












