Ernst & Young Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young (EY) Investigates Data Breach 🚨
Ernst & Young (EY) has disclosed a significant data breach after attackers compromised a third-party IT support system containing sensitive client documents and tax information. EY utilizes a third-party information technology service management platform to assist its IT personnel in providing support to teams working on tax-related tasks for clients. Support tickets submitted through this platform may include documents containing crucial client tax information.
The compromised data includes certain personal and financial information used in preparing tax filings. Currently, it remains unclear how many customers were affected by this incident.
On April 23, 2026, EY identified unusual activity within the platform. EY’s Information Security team promptly initiated its incident response procedure to assess the nature and scope of the incident, contain it, and commence remediation and recovery efforts. The company has collaborated with an independent cybersecurity firm to investigate the breach and confirm that unauthorized access has been halted, ensuring that their systems are now secure.
Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorized third party accessed the platform and downloaded documents related to several EY clients.
EY has announced that it has secured its systems, eliminated unauthorized access, and notified federal authorities. The company emphasized that there is no evidence of misuse of the exposed files or targeted attacks against specific individuals. “At this time, we are not aware of any misuse or further exposure of your personal information as a result of this incident. Furthermore, we do not have any indication that your personal information was specifically targeted,” the notification stated.
To assist affected clients, EY is offering 24 months of identity monitoring and restoration services through Experian. As of now, no ransomware group has claimed responsibility for the attack.
For more details, you can read the complete article here: Read full article