ShinyHunters Claims EY Breach; DentaQuest, Tribeca Expose Millions as Breach Costs Hit $5M Average
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed data breach at Ernst & Young (EY), threatening to release stolen data if the firm does not contact the group by July 31, 2026. The claim comes as data breaches continue to dominate headlines, with major incidents at DentaQuest and the Tribeca Film Festival exposing sensitive data on millions of individuals — including high-profile Hollywood A-listers. Meanwhile, IBM’s 2026 Cost of a Data Breach Report reveals that the average cost of a breach has reached a record $4.99 million, driven in large part by a 56% surge in AI-powered attacks.
EY Breach: Supply-Chain Attack Exposes Client Tax Data
On July 27, ShinyHunters added Ernst & Young to its data leak site, asserting that it had obtained credentials through a supply-chain attack that allowed it to breach EY’s Jira, GitHub, and Azure environments. The gang alleges that the stolen data includes not only the client tax information EY acknowledged in its breach notification but also additional, undisclosed data.
EY first disclosed the breach earlier this month, revealing that a third-party support ticket system used by its IT personnel had been compromised. According to the firm's notification, the attacker accessed the platform between March 28 and April 12, downloading multiple support tickets that “may include documents containing client tax information.” EY stated it detected unusual activity on April 23 and subsequently removed the unauthorized access, secured its systems, and notified federal law enforcement. However, the company has not named the compromised third-party platform, disclosed the specific types of data exposed, or stated how many clients were affected.
ShinyHunters told BleepingComputer that they obtained EY credentials through a supply-chain attack — meaning the credentials were likely stolen from a vendor or partner with access to EY’s systems. BleepingComputer noted that it could not independently verify the threat actors’ claims, and EY has not confirmed ShinyHunters’ involvement. The gang has set a July 31 deadline for EY to contact them, threatening to release the stolen data if the firm does not comply.
DentaQuest Data Breach: Over 23 Million Individuals Potentially Impacted
In another major breach, dental and vision benefits administrator DentaQuest has disclosed a data breach potentially affecting more than 23 million individuals. The incident was discovered on May 20, with investigators determining that hackers had network access between May 17 and May 20. During that window, attackers accessed names, addresses, Social Security numbers, member ID numbers, Medicaid and Medicare numbers, benefits provider names, diagnosis and treatment details, and billing information.
DentaQuest began sending written notification letters to at least 4.5 million people, based on filings with state attorneys general. According to the HIPAA Journal, more than 23.4 million individuals were potentially impacted; DentaQuest reportedly confirmed at least 15 million were affected.
ShinyHunters also claimed responsibility for the DentaQuest breach, leaking roughly 234 GB of alleged data. That leaked data, confirmed by HaveIBeenPwned, included email addresses, phone numbers, dates of birth, and government-issued IDs. DentaQuest is offering affected individuals 24 months of free credit monitoring, fraud consultation, and identity theft restoration services.
Tribeca Film Festival Data Exposes Hollywood A-Listers
Security researcher Jeremiah Fowler discovered four unsecured databases tied to Robert De Niro’s Tribeca Film Festival, exposing 666,369 records. Among them were private email addresses, cell phone numbers, and device information — including which version of iPhone or browser a user had, and software versions. The festival, which runs annually, left the databases publicly accessible without password protection or encryption.
Fowler, who reported the exposure before the festival’s 12-day event in June, said more than 200,000 records were attached to actors, directors, producers, media members, and festival staff. Affected celebrities include De Niro, Angelina Jolie, Jennifer Lawrence, Morgan Freeman, Winona Ryder, Martin Scorsese, Ron Howard, Neil Patrick Harris, Hilary Duff, Rami Malek, George Lucas, Michael Douglas, and Danny Boyle.
Tribeca Film Festival has since removed the databases from the internet and is investigating the situation. CyberNews noted that it remains unclear how long the information was publicly accessible or whether anyone else accessed it before being taken offline. The breach appears to have stemmed from a third-party service, not the festival itself.
Why Data Breaches Matter Now: Record Costs and the AI Factor
The wave of breaches comes at a time when the financial impact of cyberattacks is at an all-time high. IBM’s 2026 Cost of a Data Breach Report, produced by Ponemon Institute, studied 602 organizations impacted by breaches from March 2025 through February 2026. The average cost of a breach has reached $4.99 million — a 12% increase — driven primarily by a 56% surge in AI-driven attacks.
“What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive,” said Suja Viswesan, vice president of IBM Security Software, in a statement accompanying the report. The report found that 92% of organizations that suffered an AI-related breach lacked proper AI-access controls. In the United States, average breach costs hit a record $11.5 million, more than double the global average, due to higher business costs and regulatory fines.
Healthcare and Critical Infrastructure Most Exposed
Healthcare remained the most expensive industry for data breaches, averaging $6.4 million per incident, though that was down from $7.4 million in the prior year. Financial services ($6.3 million) and energy ($5.2 million) also ranked high. Malicious or criminal attacks accounted for 55% of all breaches, up nearly 8%, and more than doubled breaches caused by IT failures or human error.
The IBM report also found that 85% of breached organizations plan to increase spending on security tools and governance. Three-quarters said they will deploy AI agents at higher rates for alert triage, vulnerability management, and penetration testing.
Broader Implications: The New Normal for Cybersecurity
The convergence of supply-chain attacks, high-profile breaches, and AI-powered exploitation signals a new normal for cybersecurity. ShinyHunters’ simultaneous targeting of EY and DentaQuest demonstrates that extortion gangs are increasingly using supply-chain compromises to amplify their reach. Rather than directly attacking a major firm, attackers target smaller vendors or third-party platforms that have privileged access to the target’s data. This pattern echoes the 2023 MoveIt breach, which affected hundreds of organizations through a single software vulnerability.
For individuals, the stakes are equally high. More than 23 million people affected by the DentaQuest breach face potential identity theft, with Social Security numbers and medical details exposed. The Tribeca Film Festival breach underscores that even well-known organizations can leave sensitive data unprotected. The fact that the databases were publicly accessible without encryption highlights a common oversight: many companies fail to inventory and secure third-party systems.
The EY incident suggests that even professional services firms with robust security programs are vulnerable. The breach exposed support tickets containing tax filings, which include Social Security numbers, financial account details, and other data ideal for identity theft. A recent report from our team covered the humanitarian and economic toll of natural disasters, which, like data breaches, can devastate communities and institutions when proper safeguards fail.
The AI Arms Race in Data Breaches
IBM’s data shows that AI is reshaping both attack and defense. Attackers are using AI to automate phishing, crack credentials, and identify vulnerabilities faster. On the defensive side, organizations are deploying AI-powered security tools that monitor for anomalies, such as unusual login patterns from a third-party vendor. However, the gap between detection and remediation remains a major cost driver. Organizations that took longer than 200 days to identify and contain a breach incurred significantly higher costs.
“The priority now is to eliminate that lag — building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving,” Viswesan said.
What Changes After These Breaches?
Regulatory responses are likely to tighten. The EY, DentaQuest, and Tribeca breaches may prompt lawmakers to reconsider notification deadlines and third-party risk management requirements. The U.S. Securities and Exchange Commission already requires public companies to disclose material cybersecurity incidents, and the Federal Reserve’s recent policy decisions have economic ripple effects that can influence corporate spending on security.
For consumers, the advice remains unchanged but urgent: enable multi-factor authentication, monitor financial accounts, and use credit freezes. The DentaQuest breach alone exposed Social Security numbers on a massive scale, making identity theft a real possibility for millions.
Organizations, meanwhile, must treat every third-party connection as a potential attack vector. The ShinyHunters gang’s success against both EY and DentaQuest shows that credential theft from partners is a proven strategy. Companies should conduct regular security audits, require vendors to meet minimum security standards, and implement just-in-time access controls that limit how long a credential remains valid.
Conclusion
Data breaches are no longer abstract threats. In July 2026 alone, a global consulting firm, a dental benefits administrator, and a major cultural festival have all suffered high-profile incidents. Costs are at record highs, and AI is accelerating the pace of attacks. For businesses, the message is clear: invest in prevention, detection, and rapid response — because the cost of a breach is only going up.
Comments