Ernst & Young Data Breach Exposes Client Tax Information

Ernst & Young Data Breach Exposes Client Tax Information

First seen 17 Jul 2026, 21:52 UTC BleepingcomputerCybersecuritynewsClassactionFeeds.FeedburnerSecurityaffairs.Co+15 68.2

Article Content

Browse articles
ThreatCluster

Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026, allowed attackers to exfiltrate sensitive client documents containing personal and financial information. EY filed breach notifications with multiple state attorney generals on July 15, 2026, and began notifying affected clients on July 13, 2026. The breach affected 873 residents in Texas, 480 in Massachusetts, and 13 in Vermont, among others. The exposed data includes names, Social Security numbers, financial account information, and tax-related documents. EY has secured its systems and engaged third-party cybersecurity experts to investigate the incident. They are offering affected individuals 24 months of complimentary identity monitoring services. This incident marks EY's second major data exposure in less than a year.

Key Points: • Unauthorized access to EY's third-party IT service management platform exposed sensitive client data. • The breach affected over 1,300 individuals across multiple states, with significant personal and financial information compromised. • EY is providing 24 months of identity monitoring services to affected clients as a remediation measure.

Timeline

2026-03-28
Unauthorized access began
An unauthorized third party accessed EY's third-party IT service management platform, exfiltrating sensitive documents.
Gbhackers
2026-04-12
Unauthorized access ended
The unauthorized access to the platform was determined to have ceased by April 12, 2026, after two weeks of undetected activity.
Claimdepot
2026-04-23
Breach detected
EY's Information Security team identified anomalous activity within the platform, prompting an investigation.
Cybernews
2026-07-13
Client notifications sent
EY began mailing individual notice letters to affected clients, informing them of the breach and its implications.
Claimdepot
2026-07-15
Breach notifications filed
EY filed formal breach notifications with the California Attorney General's office and other states regarding the incident.
Gbhackers
2026-07-18
Public disclosure of breach
EY publicly confirmed the data breach and its impact on client data, including personal and financial information.
Cybernews