EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-ernst-young-tax-data-breach
046/430

File EL-0385HighResolvedData Breach / Third-Party / Supply Chain Breach

Ernst & Young Third-Party Support System Data Breach

Also filed as EY Tax Data Breach 2026 · Ernst & Young Client Tax Information Incident

Unauthorised access to a third-party IT support ticket platform used by Ernst & Young for tax-related client work, resulting in the download of documents containing client personal and financial information.

  • #professional-services
  • #tax-data
  • #financial-information
  • #pii
  • #third-party-platform
  • #big-four
Notoriety7/10
Event
28 Mar 2026
Disclosed
13 Jul 2026
Target
Ernst & Young
Status
Resolved

01Summary

Between 28 March and 12 April 2026 an unauthorised party accessed a third-party information technology service management platform used by EY IT staff to support tax-related work for clients. Support tickets on the platform sometimes contained documents with client tax information. EY detected anomalous activity on 23 April 2026, engaged external investigators, and secured the platform. Notifications to affected individuals and state regulators began in mid-July 2026. Exact number of affected individuals has not been publicly disclosed. Exposed data could include names, addresses, dates of birth, Social Security numbers, financial account numbers, credit/debit card information, and other data used in tax filings.

02Background

Ernst & Young is one of the 'Big Four' global professional services firms. The incident involved a third-party platform used internally for IT support of tax service delivery.

03Key revelations

  1. 01Client tax documents residing in an IT support ticket system were accessible to attackers for over two weeks.
  2. 02Highlights ongoing third-party / supply-chain risk even for major professional services firms.

04Technical analysis

Compromise of a third-party support ticket / IT service management platform. No public details on the exact initial access method, malware, or threat actor. Access window lasted approximately two weeks before detection.

Attack vector
Compromise of third-party support ticket platform
Attack method
Unauthorised access and document download
Initial access
Unknown (third-party platform compromise)
Exfiltration
Download of client documents from support tickets

05Threat actor

No public attribution.

06Victims and impact

Additional victims

  • Multiple EY clients whose tax-related documents were present in the support system

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Names
  • Addresses
  • Dates of birth
  • Social Security numbers
  • Financial account numbers
  • Credit / debit card information
  • Tax filing related information

08Financial damage

Notification and identity monitoring costs; potential regulatory scrutiny and client impact.

09Timeline

  1. 2026-03-28Start of unauthorised access window.
  2. 2026-04-12End of unauthorised access window.
  3. 2026-04-23Anomalous activity detected; investigation begins.
  4. 2026-07-13Client notifications begin.

10Reaction and fallout

Public reaction

Focus on the sensitivity of tax and financial data and the delayed notification timeline.

11Legal

Notifications filed with multiple US state attorneys general; federal law enforcement notified. Identity monitoring offered.

12Aftermath

Security improvements

  • Platform secured after detection
  • External forensic investigation
  • Client notifications and 24-month identity monitoring via Experian

13Significance and legacy

Significance

Notable third-party breach affecting a Big Four firm’s tax-related client data, underscoring risks in support tooling that handles sensitive documents.

14Disclosure and media

Publishing organisations

  • SecurityWeek
  • ZDNET
  • BleepingComputer
  • ClassAction.org

15Field notes

  1. 01The support ticket system used for internal IT assistance contained client tax documents.
  2. 02Exact number of affected individuals has not been publicly disclosed.

16Resolution

Unauthorised access ended by 12 April 2026. Platform secured after detection on 23 April. Notifications issued from mid-July 2026.

17Sources

Official documents

  • EY client notification letters filed with state attorneys general

References

  1. [1]EY notification letters
  2. [2]SecurityWeek
  3. [3]ZDNET
  4. [4]California and Vermont Attorney General filings
Fact sheetEL-0385

Dates

Event
28 Mar 2026
Started
28 Mar 2026
Ended
12 Apr 2026
Duration
16 days
Discovered
23 Apr 2026
Disclosed
13 Jul 2026
Resolved
23 Apr 2026
Ongoing
No

Target

Organisation
Ernst & Young LLP / EY
Type
Professional Services / Accounting Firm
Sector
Professional Services
Country
United States / Global

Actor

Motivation
Unknown (data theft)
Arrested
No
Convicted
No

Data

Sensitivity
High
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.