Ernst and Young data breach exposes client tax records through third-party IT support system

Ernst and Young has disclosed a data breach in which attackers accessed a third-party IT service management platform used by the accounting firm’s tax practice and downloaded documents containing client financial information.

The breach followed a familiar pattern: a trusted vendor’s tool, holding sensitive data as a routine byproduct of support operations, became the entry point. EY told affected clients that an unauthorized third party accessed the external support-ticketing platform between March 28 and April 12, 2026. The company detected the anomalous activity on April 23 and launched an investigation with external cybersecurity experts.

A support system as a data repository

The compromised platform was used by EY’s IT personnel to manage support requests related to tax engagements — the kind of ticketing system that exists in nearly every large organization. The problem is that support tickets routinely include attachments: tax forms, identity documents, financial statements, and other files that clients submit as part of their engagement. What is a convenience for support workers becomes a treasure trove for attackers.

Your support allows us to spend more time verifying facts and less time chasing page views.

Make a difference

“Strip away the corporate name and this story is a familiar one told again with new dates attached,” the security analysis firm Hoplon InfoSec wrote in its assessment of the incident. “A tool built for convenience quietly turned into a repository of sensitive data, nobody noticed for weeks, and now real people are left managing the fallout.”

EY notified affected individuals through filings with state regulators in California and Vermont. The firm has offered complimentary identity monitoring and restoration services through Experian, with an enrollment deadline of October 31. It has not disclosed the total number of affected clients or whether the stolen data has been used for fraud.

Growing third-party risk

EY is one of the world’s four largest professional services firms, employing more than 400,000 people across 150 countries. A data breach at this scale — involving tax records, which are among the most sensitive documents an individual or business can entrust to a third party — underscores how the attack surface of modern enterprises extends well beyond their own firewalls.

Law firms Edelson Lechtzin have announced an investigation into potential class-action claims on behalf of affected individuals. The firm noted that the breach involved documents containing “personal information and financial details related to clients’ tax filings.”

EY stated that it has secured its systems, removed the unauthorized access, and notified federal law enforcement. The company said it has “no indication that any affected individual was specifically targeted.”

Sources: Ernst & Young data breach notice (PRNewswire/Edelson Lechtzin, July 2026); EY Data Breach: Client Tax Information Exposed in Third-Party Hack (CyberSec Guru, July 2026); EY data breach exposes client tax documents (Cybernews, July 2026)

Scroll to Top