Visualização normal

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data Pierluigi Paganini
    ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to publish the stolen data unless negotiations begin by July 31. Earlier this month, EY notified several U.S. state Attorneys Gene
     

ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

29 de Julho de 2026, 10:40

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31.

The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to publish the stolen data unless negotiations begin by July 31.

Earlier this month, EY notified several U.S. state Attorneys General that attackers had gained unauthorized access to a third-party service management platform used to support tax-related operations. According to the company’s filings, the intrusion occurred between March 28 and April 12, during which threat actors downloaded documents attached to customer support tickets.

“EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.” reads the data breach notification. ” “EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts. EY has worked with an independent cybersecurity firm to investigate the incident and confirm that the unauthorized access has been stopped, and our systems are now secure. Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorized third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients.”

The exposed information includes highly sensitive personal and financial data used for tax preparation, such as names, addresses, Social Security numbers, bank account details, payment card information, and other tax-related records. EY said the incident affected data stored within the external support platform rather than its core internal systems.

While the company has not disclosed how many individuals were impacted or publicly attributed the attack, it is offering affected customers 24 months of complimentary credit monitoring, identity monitoring, and identity restoration services. EY has also remained silent on whether it has been in contact with the attackers.

The claim by ShinyHunters adds to a growing list of high-profile victims attributed to the group. In recent months, the extortion gang has claimed responsibility for breaches affecting organizations such as DentaQuest, 7-Eleven, Medtronic, and campaigns targeting Oracle PeopleSoft and Salesforce environments.

The group is known for stealing large volumes of sensitive data and using the threat of public disclosure to pressure victims into paying a ransom.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ShinyHunters)

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
  • ✇Security Affairs
  • Medtronic Notifies 3.8 Million After ShinyHunters Data Breach Pierluigi Paganini
    Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed to have stolen over 9 million records. The company did not share details on the secu
     

Medtronic Notifies 3.8 Million After ShinyHunters Data Breach

5 de Julho de 2026, 15:31

Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected.

Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information.

In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed to have stolen over 9 million records. The company did not share details on the security breach.

Medtronic is an international medical equipment giant with 90,000 employees and operations in 150 countries. It is the largest medical device maker in the world by revenue ($33.5 billion) and also develops healthcare technologies and therapies.

The company said an unauthorized party accessed data in some corporate IT systems. It found no impact on products, patient safety, operations, financial systems, or care delivery. The company noted its IT, product, and manufacturing networks are separate, and hospital networks remain independently managed and secure.

“Medtronic has determined that an unauthorized party accessed data in certain Medtronic corporate IT systems. We have not identified any impact to our products, patient safety, connections to our customers, our manufacturing and distribution operations, our financial reporting systems or our ability to meet patient needs.” reads the press release published by the company. “The networks that support our corporate IT systems, our products and our manufacturing and distribution operations are separate. Hospital customer networks remain separate from Medtronic IT networks and are secured and managed by customers’ IT teams.”

Medtronic states it had contained the breach and activated incident response with the help of external cybersecurity experts. It’s assessing if personal data was exposed and will notify affected individuals, offering them support.

On April 18, ShinyHunters added the firm to its Tor data leak site, claiming the theft of over 9 million records, including personal data and internal files. Initially, the group threatened to leak the data if the ransom was not paid by April 21, but the listing has since disappeared. The company is investigating and says it will notify and support affected individuals if data exposure is confirmed.

This week, the technology firm started sending notification letters to the impacted individuals. Medtronic said the breached data may include patients’ names, contact details, dates of birth, Social Security numbers, and health information. The company added that it has found no evidence the stolen information has been publicly released or exposed online.

“On April 15, 2026, Medtronic became aware of unusual activity on certain corporate IT systems. Medtronic launched an investigation with the assistance of leading third-party cybersecurity experts to determine the impact and scope of the incident. The investigation determined that from April 13 to April 19, 2026, an unauthorized actor accessed certain Medtronic corporate IT systems.” reads the data breach notification. “With the assistance of data review specialists, we have been working diligently to determine the types of information that may have been subject to unauthorized activity and to whom they relate. What Information Was Involved? As a patient with a Medtronic medical device, our company collects data related to you in order to provide important product-related updates and to meet our legal obligations. The investigation to date has determined that the following types of information may have been impacted: name, contact information, date of birth, Social Security number, and health-related information. We have no evidence that any of that information was posted publicly or exposed on the Internet.”

Medtronic is offering 24 months of free credit monitoring, dark web monitoring, and identity theft recovery services to those impacted.

“Medtronic is committed to and takes very seriously our responsibility to safeguard all data entrusted to us. As part of our ongoing commitment to the security of personal information in its care, Medtronic has implemented additional safeguards and continues to work with third-party cybersecurity experts to identify opportunities to further strengthen the security of its systems.” concludes the notification. “Medtronic has also worked with law enforcement and is notifying relevant regulatory authorities. In addition, we are offering you access to 24 months of complimentary credit monitoring, dark web monitoring (monitoring certain online sources for publication of personal information), and identity theft restoration services through Epiq. Details on the service and instructions for enrollment can be found in the enclosed Epiq – Privacy Solutions ID.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

Madison Square Garden Hack Exposes 26 Million Visitor Records

24 de Junho de 2026, 12:00

Madison Square Garden faces a 26M-record hack tied to visitor data, facial recognition, and security records from its venue operations, with fallout from the leak.

The post Madison Square Garden Hack Exposes 26 Million Visitor Records appeared first on TechRepublic.

  • ✇Security Affairs
  • EdTech Faces a Cybersecurity Crisis: Data Breaches Surge Pierluigi Paganini
    EdTech firms face rising cyberattacks as ShinyHunters and FulcrumSec target schools, exposing sensitive data and disrupting services. Resecurity (USA) warns the education technology (EdTech) sector has become a prime target for cybercriminals, as attacks against educational institutions and related platforms continue to escalate. Recent high-profile incidents, including attacks by groups such as ShinyHunters and FulcrumSec, highlight the vulnerability of educational organizations and the inc
     

EdTech Faces a Cybersecurity Crisis: Data Breaches Surge

17 de Junho de 2026, 06:16

EdTech firms face rising cyberattacks as ShinyHunters and FulcrumSec target schools, exposing sensitive data and disrupting services.

Resecurity (USA) warns the education technology (EdTech) sector has become a prime target for cybercriminals, as attacks against educational institutions and related platforms continue to escalate. Recent high-profile incidents, including attacks by groups such as ShinyHunters and FulcrumSec, highlight the vulnerability of educational organizations and the increasing sophistication of cyber extortion tactics.

Today (June 16, 2026) — ShinyHunters announced new victims, including, but not limited to Glendale Community College, Moody Bible Institute, Illinois Central College, Houston City College. The gang also stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. Infinite Campus is an education technology (EdTech) company that provides a student information system (SIS) to over 3,200 school districts across the United States, managing data for 11 million students in 46 states.

In another devastating incident, the group FulcrumSec has claimed responsibility for a massive ransomware attack targeting the Global Schools Foundation (GSF), an international network of educational institutions headquartered in Singapore. The attack, which occurred in early June 2026, resulted in large-scale data exfiltration from critical systems across GSF’s schools in multiple countries, disrupting operations, and leaving students and staff unable to access essential services.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, EdTech Faces)

ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack

Google says ShinyHunters exploited Oracle PeopleSoft zero-day to steal data from 100+ organisations, with universities making up most victims.

ShinyHunters Leak 40GB of University of Nottingham Student Data

ShinyHunters hackers leak 40GB of University of Nottingham personal and financial data, allegedly impacting 450,000 students and staff records.

FBI warns students and staff that ShinyHunters may come knocking after Canvas breach

20 de Maio de 2026, 05:28
Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future. Read more in my article on the Hot for Security blog.
  • ✇Graham Cluley
  • Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities Graham Cluley
    Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap. Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoi
     

Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

13 de Maio de 2026, 20:05
Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap. Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoiler: it isn't him, the tips aren't real, and you're about to be scammed. Plus we chat to Mike Nichols of Elastic, about how the SOC isn't dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users - it's the bots acting on their behalf. All this and more in episode 467 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak

Instructure has reached an agreement with the ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records from a public leak.

Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended

ShinyHunters says its shinyhunte.rs domain was suspended after the Canvas LMS attacks, forcing the group to move fully to its dark web (.onion) site.
  • ✇Firewall Daily – The Cyber Express
  • Instructure Confirms Canvas Cybersecurity Incident, User Data Accessed Samiksha Jain
    A Canvas cybersecurity incident has disrupted services at Instructure, the company behind the widely used Canvas platform, raising concerns among educational institutions over potential data exposure and service interruptions. The Canvas cybersecurity incident first came to light late Friday, when Instructure disclosed that it had detected unauthorized activity linked to a cyberattack. The company said it immediately launched an investigation with the support of external forensic experts to d
     

Instructure Confirms Canvas Cybersecurity Incident, User Data Accessed

Canvas cybersecurity incident

A Canvas cybersecurity incident has disrupted services at Instructure, the company behind the widely used Canvas platform, raising concerns among educational institutions over potential data exposure and service interruptions. The Canvas cybersecurity incident first came to light late Friday, when Instructure disclosed that it had detected unauthorized activity linked to a cyberattack. The company said it immediately launched an investigation with the support of external forensic experts to determine the scope and impact. By Saturday, Chief Information Security Officer Steve Proud confirmed that attackers had gained access to certain user data from some institutions. The exposed information includes names, email addresses, student identification numbers, and messages exchanged within the platform. Proud emphasized that the incident has been contained. He added that the response involved revoking privileged credentials and access tokens, deploying security patches, and increasing system-wide monitoring. However, some of these defensive measures led to temporary disruptions in services, particularly tools dependent on API keys.

Canvas Cybersecurity Incident: No Financial or Sensitive Identity Data Compromised

Despite the data breach, Instructure stated that there is currently no evidence that highly sensitive data such as passwords, financial information, government identifiers, or dates of birth were accessed. The company noted it will notify affected institutions if any new findings emerge. Canvas is used extensively by schools, universities, and enterprises to manage coursework, host educational content, and facilitate communication between students and educators. The scale of its usage has amplified concerns around the potential reach of the incident.

ShinyHunters Claims Large-Scale Data Theft

The cybercriminal group ShinyHunters claimed responsibility for the attack on Sunday, alleging it had stolen 3.6 terabytes of data affecting more than 9,000 schools. These claims have not been independently verified, and Instructure has not publicly responded to the group’s assertions. [caption id="attachment_111847" align="aligncenter" width="657"]Canvas Cybersecurity Incident Source: X[/caption] Such claims, if validated, could significantly expand the scope of the Canvas cybersecurity incident beyond initial disclosures. For now, the company maintains that its investigation is ongoing.

Ongoing Maintenance and Service Restoration Efforts

Instructure has been providing regular updates as it works to stabilize systems affected by the Canvas cybersecurity incident. As of May 5, Canvas Data 2 and Beta services have largely been restored, while the Test environment remains under maintenance. Earlier updates indicated that some users experienced disruptions due to reissued application keys, a precautionary measure taken to enhance security. Users were required to re-authorize access to certain tools, with updated keys identifiable by timestamps. The company also confirmed that it rotated certain keys even without evidence of misuse, reflecting a cautious approach to securing its infrastructure.

Continued Monitoring as Investigation Proceeds

The investigation into the Canvas cybersecurity incident remains active, with Instructure continuing to monitor its systems and assess potential risks. The company has reiterated its commitment to transparency and stated that updates will be shared as new information becomes available. For institutions relying on Canvas, the incident highlights the operational impact of cybersecurity threats on critical education platforms. While services are gradually being restored, the focus now shifts to understanding the full extent of the breach and preventing similar incidents in the future.

ShinyHunters Leaks Data of Udemy, Zara, 7-Eleven in Salesforce Linked Breach

ShinyHunters has leaked data linked to Udemy, Zara, and 7-Eleven, with claims of exposed Salesforce records and cloud-based systems.

Vercel Breach Linked to Context.ai, ShinyHunters Says It’s Not Involved

Vercel confirms a breach linked to Context.ai as a hacker lists alleged data for $2M. ShinyHunters denies involvement and flags imposters.
❌
❌