Bleepingcomputer
Ernst & Young Data Breach Exposes Client Tax Information
Article Content
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026, allowed attackers to exfiltrate sensitive client documents containing personal and financial information. EY filed breach notifications with multiple state attorney generals on July 15, 2026, and began notifying affected clients on July 13, 2026. The breach affected 873 residents in Texas, 480 in Massachusetts, and 13 in Vermont, among others. The exposed data includes names, Social Security numbers, financial account information, and tax-related documents. EY has secured its systems and engaged third-party cybersecurity experts to investigate the incident. They are offering affected individuals 24 months of complimentary identity monitoring services. This incident marks EY's second major data exposure in less than a year.
Key Points: • Unauthorized access to EY's third-party IT service management platform exposed sensitive client data. • The breach affected over 1,300 individuals across multiple states, with significant personal and financial information compromised. • EY is providing 24 months of identity monitoring services to affected clients as a remediation measure.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.