ShinyHunters Adds EY, RingCentral, and Brinks Home to Data Leak Site

ShinyHunters has added EY, RingCentral, and Brinks Home to its leak site while announcing that its CDN infrastructure has been restored ahead of future data releases.
Screenshot of the ShinyHunters leak site showing newly added listings for Ernst & Young, RingCentral, and Brinks Home alongside a notice stating the group’s CDN mirrors are back online and torrent releases are being prepared.
ShinyHunters updated its leak site with new listings for Ernst & Young, RingCentral, and Brinks Home while announcing that its CDN mirrors have been restored and additional data releases are being prepared.

The ShinyHunters extortion group has updated its data leak site with three new organizations, issuing what it describes as “final warning” notices to Ernst & Young (EY), RingCentral, and Brinks Home before the alleged publication of stolen data.

The updates, posted on July 27, set deadlines ranging from July 30 to July 31 and warn that the group intends to release the allegedly stolen data if negotiations do not take place. Unlike the other newly listed organizations, EY had already disclosed a cybersecurity incident earlier this month involving a compromised third-party support ticket platform. At the time of publication, RingCentral and Brinks Home had not issued public statements regarding the claims.

ShinyHunters claims responsibility for disclosed EY breach

ShinyHunters claims responsibility for the previously disclosed Ernst & Young incident, stating the company has until July 31 to make contact before the group publishes the purportedly stolen files.

Earlier this month, EY notified affected customers that an unauthorized third party accessed a third-party support ticket system used by its IT personnel between March 28 and April 12. According to the company, the attackers downloaded documents that may have contained personal and financial information used in tax preparation. EY said it secured the affected platform, notified law enforcement, and began offering impacted customers identity monitoring services.

At the time of EY’s disclosure, no ransomware or extortion group had publicly claimed responsibility for the incident. ShinyHunters’ latest leak-site posting appears to be the first public attempt to attribute the breach to the group.

The post reads in part:

“Yes it was us. Now come talk to us. We have been trying to reach you. If you do not come talk to us within the given deadline, we fully and completely intend to release all the data and files.”

The group also warns of additional “digital problems” if negotiations do not occur before the deadline, although it does not elaborate on what those threats entail.

RingCentral and Brinks Home also listed

RingCentral was simultaneously added to the leak site with a July 30 deadline. ShinyHunters claims to have compromised company data but does not specify the amount of information allegedly stolen, instead stating only that “over XX of data was compromised.”

Brinks Home, listed as BH Security LLC (brinkshome.com), was also added with the same July 30 deadline. In that listing, the group claims to possess more than 4.9 million Salesforce records containing personally identifiable information.

Neither listing was accompanied by publicly available evidence sufficient to independently verify the alleged compromises.

Leak site infrastructure restored

Alongside the new victim listings, ShinyHunters published an operational update regarding its content delivery infrastructure.

According to the notice, all CDN mirrors are back online following a service disruption that began on July 25. The group says content synchronization across its mirrors remains in progress and that it is preparing torrent releases for its leaked datasets. It also encouraged visitors to seed the files once they become available.

While such announcements cannot be independently verified, the update suggests the group is restoring its distribution infrastructure ahead of future data releases.

Pressure campaign continues

The newly published deadlines are consistent with ShinyHunters’ use of public leak sites to pressure organizations into entering negotiations before allegedly stolen data is released.

While EY has acknowledged a breach involving a third-party support platform, it has not publicly attributed the incident to ShinyHunters. RingCentral and Brinks Home had not issued public statements addressing the group’s claims at the time of publication.

BreachNews will continue monitoring the listings for any published evidence, company responses, or data releases.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site