The data extortion group ShinyHunters added three well known American companies to its leak site on July 27, 2026: the professional services firm Ernst and Young, the cloud communications provider RingCentral, and BH Security, the operator of the Brinks Home alarm brand. All three are claims posted by the gang itself. A leak site entry is a pressure tactic, not proof that a breach happened or that the stolen data is what the attackers say it is.
The listings were captured through leak site monitoring that feeds the IntelFusions incident dataset, which records new victim postings as extortion crews publish them. IntelFusions has not seen a public statement from any of the three companies about the claims.
Why the big names deserve a second look
ShinyHunters is a data theft brand rather than a ransomware crew that encrypts files. Its recent activity has centered on pulling data out of cloud platforms and third party services instead of grinding through corporate networks. In June the group was linked to intrusions at universities through an Oracle PeopleSoft zero day, and in early July it claimed the test equipment maker Fluke and the distributor Ingram Content. It also surfaced in the extortion claims around medical device maker Abbott.
That pattern matters for how to read the newest entries. When a company the size of Ernst and Young appears on a data theft leak site, the data on offer often comes from a shared software as a service tenant, a marketing or support platform, or a supplier, rather than from the company's core systems. It can still be genuinely sensitive, and it can still be that company's data. But the brand in the headline and the system that was actually breached are frequently not the same organization.
Anubis lists a Coca-Cola subsidiary
The same day, the Anubis ransomware operation posted an entry describing a major data breach at a company owned by Coca-Cola, naming Fairlife, the US dairy brand owned by The Coca-Cola Company. Anubis has kept up a steady run of listings through July across the United States and France, adding the French insurance broker Prelys Courtage on July 28.
What to do with an unverified claim
Treating these listings as confirmed breaches is a mistake, but so is ignoring them. Practical steps for anyone with exposure to a named brand:
- Inventory the third party platforms that hold your data alongside a large partner's, and review which connected apps and OAuth grants can export records in bulk.
- Watch for unusual bulk export or report generation activity in cloud CRM and support tooling, which is where this style of theft usually shows up first.
- Expect social engineering. Claimed breaches at recognizable brands get reused as pretexts for help desk and vendor impersonation calls within days.
- If you are a customer of a named company, wait for the company's own statement before acting on any email or call that references the incident.
The concentration is worth noting on its own. All three ShinyHunters listings and the Fairlife entry are United States organizations, continuing a run of large American brands appearing on data theft sites through July.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.