The infamous ShinyHunters extortion group has claimed responsibility for the recently disclosed Ernst & Young (EY) data breach.

Earlier this month, the professional services giant reported to the Attorney General’s Offices in several states that hackers stole personal and financial information from a third-party service management platform used to support tax-related work.

Between March 28 and April 12, the company said, the attackers downloaded the tax-related documents of Ernst & Young clients that were included in support tickets submitted through the platform.

Client names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other types of information used for tax filings were compromised in the data breach.

The company is providing the potentially impacted individuals with 24 months of free credit monitoring, identity monitoring, and identity restoration services.

Ernst & Young has not shared details on the number of potentially affected individuals, nor did it say who was behind the attack. The company has not responded to a SecurityWeek inquiry on the matter.

On Monday, ShinyHunters added the professional services firm to its Tor-based leak site, threatening to release all the stolen data if Ernst & Young does not make contact by July 31.

With a history of following through on its threats, the extortion group has been linked to multiple high-profile data breaches recently, including the University of Nottingham, DentaQuest, 7-Eleven, Medtronic, Wynn Resorts, and the Oracle PeopleSoft and Salesforce campaigns.

Related: Origin Energy Data Breach Affects 900,000 Australians

Related: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Related: MCBS Data Breach Affects 1.2 Million Individuals

Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks