Third-party IT service management platform and Ernst & Young: EY says client tax data exposed in third-party IT software breach

Third-party IT service management platform and Ernst & Young: EY says client tax data exposed in third-party IT software breach

EY Notifies Clients of Data Breach After Third-Party Platform Compromise

Ernst & Young (EY) has begun notifying affected individuals following a data breach involving a third-party IT service management platform used by its tax practice. The incident exposed personal and financial information belonging to multiple tax clients, though EY reports no evidence of misuse to date.

The breach was detected on April 23, 2026, after EY’s Information Security team identified anomalous activity on the platform. An investigation, supported by an independent cybersecurity firm, determined that unauthorized access occurred between March 28 and April 12, 2026, during which attackers downloaded client-related documents. The affected systems were secured, and federal law enforcement was notified.

The compromised platform, used to manage support tickets for tax-related engagements, may have contained sensitive documents, including personal and financial details tied to tax filings. While the exact data exposed varies by individual, EY’s notification letters dated July 13, 2026 confirm that affected parties will receive specific details about their compromised information.

As part of its response, EY is offering 24 months of complimentary Experian IdentityWorks credit monitoring and identity restoration services to impacted individuals, with enrollment required by October 31, 2026. The firm has not disclosed the number of affected clients, the identity of the third-party provider, or the threat actor responsible for the breach.

Source: https://cyberinsider.com/ey-says-client-tax-data-exposed-in-third-party-it-software-breach/

Cireson cybersecurity rating report: https://www.rankiteo.com/company/cireson

EY cybersecurity rating report: https://www.rankiteo.com/company/ernstandyoung

"id": "CIRERN1784299363",
"linkid": "cireson, ernstandyoung",
"type": "Breach",
"date": "3/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Accounting, Tax, Advisory',
                        'name': 'Ernst & Young (EY)',
                        'type': 'Professional Services'}],
 'attack_vector': 'Third-party platform compromise',
 'customer_advisories': '24 months of complimentary Experian IdentityWorks '
                        'credit monitoring and identity restoration services '
                        '(enrollment by October 31, 2026)',
 'data_breach': {'data_exfiltration': True,
                 'file_types_exposed': 'Tax-related documents',
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal information',
                                              'Financial information']},
 'date_detected': '2026-04-23',
 'date_publicly_disclosed': '2026-07-13',
 'description': 'Ernst & Young (EY) notified affected individuals following a '
                'data breach involving a third-party IT service management '
                'platform used by its tax practice. The incident exposed '
                'personal and financial information belonging to multiple tax '
                'clients, with no evidence of misuse reported to date.',
 'impact': {'data_compromised': 'Personal and financial information',
            'identity_theft_risk': 'High',
            'systems_affected': 'Third-party IT service management platform '
                                '(tax practice support tickets)'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'root_causes': 'Unauthorized access to third-party '
                                           'platform'},
 'references': [{'source': 'EY Notification Letters'}],
 'response': {'communication_strategy': 'Notification letters to affected '
                                        'individuals',
              'containment_measures': 'Affected systems secured',
              'incident_response_plan_activated': True,
              'law_enforcement_notified': True,
              'third_party_assistance': 'Independent cybersecurity firm'},
 'title': 'EY Data Breach After Third-Party Platform Compromise',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.