Ernst & Young Breach: Third-Party IT Support Platform Compromise Exposes Client Tax Data

Ernst & Young Breach: Third-Party IT Support Platform Compromise Exposes Client Tax Data

Ernst and Young has disclosed a data breach after a third party IT support ticketing platform was compromised, allowing an unauthorized party to download documents containing sensitive client tax and financial information over a two week window. The Big Four firm filed breach notifications on July 15, 2026.

P
Priya Sharma
13 min read
0 views
Premium
Source: Rescana
Expert Reviewed
EEAT Compliant
5 Key Takeaways
Executive Summary

Summary

Ernst and Young has disclosed a data breach after a third party IT support ticketing platform was compromised, allowing an unauthorized party to download documents containing sensitive client tax and financial information over a two week window. The Big Four firm filed breach notifications on July 15, 2026.

Key Takeaways

  • 1
    EY detected the breach on April 23, 2026, but data was accessed between March 28 and April 12
  • 2
    A third party IT support ticketing platform was the entry point, not EY own infrastructure
  • 3
    Sensitive client tax and financial documents were downloaded by the attacker
  • 4
    No ransomware group has claimed responsibility and the attack method remains undisclosed
  • 5
    Breach notifications were filed with the California AG on July 15, 2026

Ernst and Young, one of the world largest professional services and consulting firms, has disclosed a data breach following the compromise of a third party IT support ticket system. The breach exposed sensitive client tax and financial information over a roughly two week period.

The Breach Timeline

The breach was detected on April 23, 2026, but the unauthorized access had occurred earlier, between March 28 and April 12, 2026. During this window, an unauthorized third party accessed and downloaded documents containing sensitive client tax and financial information through a third party IT service management platform used by EY IT personnel to support internal teams handling tax related client work.

EY filed breach notification letters with the California Attorney General office on July 15, 2026, dated July 13, 2026, confirming the incident scope. The firm uses a third party platform for IT support and service management, a common practice in large enterprises. The breach originated from the compromise of that platform rather than EY own infrastructure.

The Third Party Risk Epidemic

The EY breach is the latest in a growing wave of third party supply chain compromises. The pattern is consistent. Attackers target a vendor or service provider that has trusted access to a larger organization systems, using that trusted relationship as a bridge to reach sensitive data. In this case, the IT support ticketing platform held sensitive documents because EY IT teams used it to manage support requests related to client tax work.

What makes this particularly damaging is the type of data exposed. Tax and financial information is among the most sensitive data a consulting firm handles. It can include client financial statements, tax returns, audit workpapers, and personally identifiable information for client employees. This data is valuable for identity theft, financial fraud, and corporate espionage.

Attribution and Method

At the time of disclosure, no ransomware or extortion group had claimed responsibility for the breach. The specific method of compromise, how the attacker gained access to the third party platform, remains undisclosed. EY has not revealed the exact number of individuals or clients affected.

The Big Four Target Profile

As a Big Four accounting firm, EY handles enormous volumes of confidential client data across thousands of enterprise clients. A breach of this nature has cascading implications. Affected clients may face their own regulatory obligations, the compromised data could be leveraged in targeted attacks against EY clients, and trust in the professional services sector takes a hit. The incident highlights that even organizations with sophisticated cybersecurity programs are only as secure as their weakest third party link.

Beginner Friendly

Think of this like a thief who could not break into a bank directly, so instead they broke into the locksmith company that makes the bank keys. Ernst and Young is one of the biggest accounting firms in the world, handling highly sensitive financial information for major companies. The hackers did not attack EY directly. They attacked a separate tech company that EY uses for its IT support system. Through that back door, they were able to download private financial documents about EY clients. The scary part is that the breach went undetected for two weeks.

Premium Content

Unlock advanced insights and get unlimited access to all premium AI content with a subscription.

Sources & References

Frequently Asked Questions

Quick answers about this story

P

Priya Sharma

AI Writer & Researcher

Reviewed by OneStep AI editorial team