2 Remove Virus

EY discloses data breach after attackers access clients’ tax documents

Ernst & Young (EY) has disclosed a data breach after attackers gained unauthorized access to a third-party IT service management platform used to support the firm’s tax operations. The incident exposed documents uploaded through support tickets, some of which contained sensitive client tax information and financial records. EY has begun notifying affected individuals, although it has not disclosed how many people were impacted or identified the third-party provider involved.

 

 

According to the notification sent to affected clients, suspicious activity was detected on April 23, 2026. EY immediately launched an internal investigation with the assistance of external cybersecurity specialists. The investigation determined that an unauthorized party had access to the platform between March 28 and April 12, 2026, during which time documents belonging to a number of clients were downloaded.

The compromised platform was used by EY’s information technology staff to provide technical support for teams handling client tax work. Support requests submitted through the system could include attachments containing tax-related documents, meaning the exposed files may have contained personal and financial information provided by clients as part of tax preparation and advisory services. EY has not published a complete list of the data types involved because the contents vary depending on the individual support ticket.

In notices submitted to state regulators, EY said the exposed information may include names and documents containing personal or financial details related to tax filings. Reports filed with U.S. state authorities indicate that, in some cases, the compromised records may also have contained Social Security numbers, financial account information, payment card details, and other sensitive personal data.

The company said it secured the affected platform after discovering the intrusion and implemented additional security measures to reduce the risk of similar incidents. EY also reported the breach to law enforcement and is offering complimentary identity protection and credit monitoring services to affected individuals. The firm stated that it is not aware of any misuse of the exposed information but encouraged recipients of the notification to monitor financial accounts, review credit reports, and remain alert for phishing attempts or identity theft.

EY is one of the world’s four largest accounting and professional services firms, providing tax, audit, consulting, and advisory services to organizations in more than 150 countries. The company has not attributed the attack to a specific threat actor, and no ransomware group has publicly claimed responsibility for the incident. The investigation remains ongoing, and EY has not indicated whether additional notifications will be issued as investigators continue determining the full scope of the breach.