01Summary
Between 28 March and 12 April 2026 an unauthorised party accessed a third-party information technology service management platform used by EY IT staff to support tax-related work for clients. Support tickets on the platform sometimes contained documents with client tax information. EY detected anomalous activity on 23 April 2026, engaged external investigators, and secured the platform. Notifications to affected individuals and state regulators began in mid-July 2026. Exact number of affected individuals has not been publicly disclosed. Exposed data could include names, addresses, dates of birth, Social Security numbers, financial account numbers, credit/debit card information, and other data used in tax filings.
02Background
Ernst & Young is one of the 'Big Four' global professional services firms. The incident involved a third-party platform used internally for IT support of tax service delivery.
03Key revelations
- 01Client tax documents residing in an IT support ticket system were accessible to attackers for over two weeks.
- 02Highlights ongoing third-party / supply-chain risk even for major professional services firms.
04Technical analysis
Compromise of a third-party support ticket / IT service management platform. No public details on the exact initial access method, malware, or threat actor. Access window lasted approximately two weeks before detection.
- Attack vector
- Compromise of third-party support ticket platform
- Attack method
- Unauthorised access and document download
- Initial access
- Unknown (third-party platform compromise)
- Exfiltration
- Download of client documents from support tickets
05Threat actor
No public attribution.
06Victims and impact
Additional victims
- Multiple EY clients whose tax-related documents were present in the support system
Countries affected
- United States
07Data exposed
Data types
- PII
- Names
- Addresses
- Dates of birth
- Social Security numbers
- Financial account numbers
- Credit / debit card information
- Tax filing related information
08Financial damage
Notification and identity monitoring costs; potential regulatory scrutiny and client impact.
09Timeline
- 2026-03-28Start of unauthorised access window.
- 2026-04-12End of unauthorised access window.
- 2026-04-23Anomalous activity detected; investigation begins.
- 2026-07-13Client notifications begin.
10Reaction and fallout
Public reaction
Focus on the sensitivity of tax and financial data and the delayed notification timeline.
11Legal
Notifications filed with multiple US state attorneys general; federal law enforcement notified. Identity monitoring offered.
12Aftermath
Security improvements
- Platform secured after detection
- External forensic investigation
- Client notifications and 24-month identity monitoring via Experian
13Significance and legacy
Significance
Notable third-party breach affecting a Big Four firm’s tax-related client data, underscoring risks in support tooling that handles sensitive documents.
14Disclosure and media
Publishing organisations
- SecurityWeek
- ZDNET
- BleepingComputer
- ClassAction.org
15Field notes
- 01The support ticket system used for internal IT assistance contained client tax documents.
- 02Exact number of affected individuals has not been publicly disclosed.
16Resolution
Unauthorised access ended by 12 April 2026. Platform secured after detection on 23 April. Notifications issued from mid-July 2026.
17Sources
Official documents
- EY client notification letters filed with state attorneys general
References
- [1]EY notification letters
- [2]SecurityWeek
- [3]ZDNET
- [4]California and Vermont Attorney General filings









