EY Data Breach: What Was Exposed and What to Do

Ernst & Young (EY), one of the Big Four accounting and advisory firms, is notifying clients of a data breach after an unauthorised party accessed a third-party IT support platform its staff use and downloaded documents. The breach centres not on EY’s audit systems but on a support-ticket tool, where client tax documents had been attached. Attackers had access for about two weeks in early 2026 before the activity was detected, and the exposed information includes names, addresses, Social Security numbers, and financial account details.

This is a developing story. Below is what has been confirmed, what EY has not yet disclosed, and what the incident means for organisations and individuals, kept deliberately free of alarmism.

What happened

EY operates in more than 150 countries and handles tax and financial data at scale. The compromised system was a third-party service-management platform, the kind of ticketing tool internal IT teams use to track and resolve support requests.

The weakness was not that the platform existed, but what passed through it. Support tickets routinely carried attachments containing sensitive client tax information. A single helpdesk queue can therefore accumulate sensitive files across many clients, and that is what an unauthorised party reached, downloading multiple documents belonging to a number of EY clients before anyone noticed.

Timeline

Date Event
28 March 2026 Unauthorised access to the support platform begins.
12 April 2026 End of the access window. Documents were downloaded during this roughly two-week period.
23 April 2026 EY detects anomalous activity and starts incident response with an independent cybersecurity firm, about three weeks after the intrusion first began.
13 July 2026 Date on the client notification letter.
15 July 2026 Breach notifications filed with the California and Texas Attorneys General; wider public reporting follows.

What information was exposed

The documents held personal and financial details contained in, or used to prepare, client tax filings. Reporting based on state Attorney General filings lists names, addresses, Social Security numbers, account numbers, and credit and debit card numbers, alongside other tax-preparation data. Some records also related to individuals’ investment holdings with EY’s institutional clients, meaning some affected people may never have dealt with EY directly.

The mix is what makes this significant. Tax records bundle identifying data (name, address, Social Security number) with financial data (accounts, card numbers) in one place, the combination that raises the risk of identity theft, tax-refund fraud, and convincing, targeted phishing. If you want a refresher on spotting those follow-up scams, see our guide on how to spot a phishing email in 30 seconds.

EY’s response

According to its notification, EY has secured the affected systems and removed the unauthorised access, engaged external cybersecurity specialists to determine the scope, notified law enforcement, and offered affected clients two years of identity monitoring and restoration services. EY also states it has found no evidence so far that the data has been misused, and no indication that specific individuals were deliberately targeted.

What EY has not said

It is worth being clear about the gap between confirmed facts and open questions. As of publication, EY has not disclosed:

  • which vendor’s platform was involved;
  • how many people are affected in total;
  • the geographic scope, or whether this reaches beyond US clients; or
  • who was responsible. No threat actor has been named, and no ransomware or extortion group has claimed the attack.

We will update this post as EY or investigators release further detail.

Context: a pattern in the plumbing

This incident is separate from two earlier events that will be mentioned alongside it: an October 2025 disclosure of a 4TB database backup tied to an EY entity found publicly accessible on cloud storage (a misconfiguration, not this intrusion), and the 2023 MOVEit Transfer mass-exploitation campaign, which affected EY among tens of thousands of organisations worldwide.

Taken together, they point to a pattern worth naming plainly: for a firm that processes financial data at scale, the recurring weak point is the third parties and the plumbing, backups, file-transfer tools, and support platforms, rather than the core systems everyone assumes are the target.

Illustration for the Ernst & Young data breach: client tax documents exposed through a third-party IT support platform.
The EY breach exposed client tax data through a third-party support platform, not EY’s core audit systems.

Why it matters:

Beginner

If you receive a breach letter, take the free monitoring that is offered before the deadline, and consider placing a credit freeze, the single most effective step against someone opening accounts in your name, which is free to place and lift. Be more sceptical than usual of unexpected emails, calls, or texts. Exposure raises risk; it does not guarantee harm, and a few steps meaningfully lower it.

Business

Your vendor’s breach is your notification problem. If a data processor you rely on is compromised, the duty to assess and notify still lands on you as the data controller. Know where your helpdesk ticket attachments live, who can read them, and how long they are kept, and ask whether you could meet a 72-hour notification clock if a vendor told you late.

Professional

Roughly three weeks passed before detection here. Monitoring and data-egress alerting belong on the third-party and SaaS layer, not only at the network edge, and third-party access deserves the same review as internal systems. Treat IT service-management platforms as sensitive data stores, because that is what ticket attachments quietly turn them into.

The legal and regulatory picture

Litigation is already forming. A US class-action firm has announced an investigation into potential data-privacy claims arising from the breach. In keeping with a no-hype approach, it is worth stating plainly that an investigation by a plaintiff firm is not a finding of liability. It is a routine, expected step after any large breach involving sensitive data, and it signals that the real cost of this incident to EY will play out over months, in notifications, monitoring, and legal process, rather than in a single headline.

The wider point is about obligations, not one jurisdiction. Tax and financial data attract some of the strictest breach-notification rules anywhere, and a firm operating in 150+ countries can trip many of them at once:

  • United States. A patchwork of state breach-notification laws (the California and Texas filings are how much of this became public), plus sector rules where financial data is involved.
  • EU and UK (GDPR). The benchmark many other laws copy: a controller must notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, and inform affected individuals without undue delay where the risk is high.
  • A widening circle of newer, GDPR-inspired laws. Across Asia-Pacific, the Middle East, Africa, and Latin America, these increasingly impose their own notification duties and reach organisations extraterritorially. India’s DPDP Act, Brazil’s LGPD, and Sri Lanka’s PDPA are examples, and a single breach can engage several regimes at once.

Sources & references

Reporting based on breach notifications filed with the California and Texas Attorneys General, and EY’s client notification letter (dated 13 July 2026).

Last verified: 26 July 2026. This is a developing story; details may change as EY and investigators disclose more. Spotted an error? Report it to our editorial team.