Key Takeaways

- Attackers accessed EY's third-party support ticket system for roughly two weeks, stealing tax-related client data
- EY is offering affected clients 24 months of free Experian IdentityWorks and Identity Restoration services
- Victims should consider freezing their credit and signing up for an IRS identity protection PIN before October 31, 2026
Ernst & Young has disclosed a data breach that gave attackers access to client tax information for roughly two weeks. The breach, which occurred between March 28 and April 12, targeted a third-party support ticket system the Big Four accounting firm uses to handle tax work. EY filed breach notices with California, Massachusetts, and Vermont on July 15 and has begun notifying affected clients.

How did the Ernst & Young breach happen?
The intrusion hit a third-party IT platform that EY teams use to submit support tickets. Those tickets often contain sensitive customer data related to tax filings. For two weeks, the attacker downloaded records "pertaining to a number of EY clients," according to the company's notice.
EY detected suspicious activity on April 23, more than a week after the unauthorized access ended. The firm hired an outside cybersecurity company to investigate. The support ticket system has since been secured, but EY hasn't disclosed whether malware was involved or identified the responsible party.
This pattern, a vendor breach exposing client data, has become the dominant attack vector for sophisticated threat actors. Going after service providers like accounting firms gives attackers access to hundreds or thousands of downstream targets in a single compromise.
Another major 2026 data breach that exposed millions of user records
What data was stolen?
EY's notification letter references "certain financial information contained in or used to prepare tax filings." The firm hasn't disclosed the full list of data types, but tax filings typically require names, addresses, Social Security numbers, and financial account details. Each victim's letter should list their specific exposed data points.
The company states it is "not aware of any misuse or further exposure" of personal information and says there's no "indication [your] personal information was specifically targeted." That's standard breach disclosure language, not a guarantee. Tax data is valuable precisely because it contains everything needed for identity theft and fraudulent tax filings.
How do I know if I'm affected?
If you're an EY tax client, watch your mail. The firm is sending letters to affected individuals that detail exactly what information was stolen. EY hasn't disclosed how many clients were hit, so the notification rollout may take time. Not receiving a letter yet doesn't mean you're safe.
EY is offering two free Experian services for 24 months: IdentityWorks (credit monitoring) and Identity Restoration. You'll need the code in your letter to activate these services before October 31, 2026. That deadline is firm.
What should affected clients do now?
- Activate the free Experian services using your letter's code before the October 31, 2026 deadline
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) until the scope of the breach is clearer
- Sign up for an IRS Identity Protection PIN to prevent anyone from filing taxes using your Social Security number
- Monitor your bank accounts and credit card statements for unauthorized transactions
- Request your free annual credit reports and check for accounts you didn't open
The IRS identity protection PIN is the most important step if your Social Security number was exposed. It blocks anyone from filing a federal tax return in your name without the PIN, which is the primary risk when tax data leaks.
How AI is being deployed to find and fix security vulnerabilities
Why third-party breaches keep happening
This breach follows a familiar script. Large enterprises outsource functions to vendors, those vendors handle sensitive data, and attackers target the vendor as the weakest link. A support ticket system might seem low-priority, but any system that touches customer data is a target.
The gap between the breach end date (April 12) and EY's detection (April 23) shows how hard it is to spot intrusions in third-party systems. Companies often lack visibility into vendor security controls, and vendors may not have the monitoring capabilities of their larger clients.
Logicity's Take
For CTOs and security leaders, this breach is a reminder to audit your vendor ecosystem aggressively. Ask your vendors: How do you monitor for unauthorized access? What's your mean time to detect an intrusion? The two-week dwell time here is troubling but not unusual. Companies handling tax data or other sensitive records should require vendors to meet specific detection and response benchmarks, not just check compliance boxes. The real risk isn't EY itself. It's every third-party tool in your stack that touches customer data.
New security feature designed to detect unauthorized access
Frequently Asked Questions
How long did attackers have access to EY's system?
Attackers had access to the third-party support ticket system from March 28 to April 12, roughly two weeks. EY detected the suspicious activity on April 23.
What should I do if I received an EY breach notification letter?
Activate the free Experian IdentityWorks and Identity Restoration services using your letter's code before October 31, 2026. Consider freezing your credit and signing up for an IRS identity protection PIN.
Is my Social Security number at risk from the EY breach?
EY hasn't disclosed the specific data types stolen. However, tax filings typically require Social Security numbers, so it's possible. Your notification letter should list your specific exposed data.
How do I sign up for an IRS identity protection PIN?
Visit the IRS website and use their Get an IP PIN tool. This prevents anyone from filing a federal tax return using your Social Security number without your unique PIN.
Did EY disclose how many clients were affected?
No. EY has not disclosed the total number of affected clients. Breach notices were filed in California, Massachusetts, and Vermont, but the full scope remains unknown.
Need Help Implementing This?
If your organization needs to strengthen vendor security assessments or incident response capabilities, Logicity can connect you with cybersecurity consultants who specialize in third-party risk management. Contact us for recommendations.
Source: Latest news
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
Humanity Just Went Farther Into Space Than Ever Before — And Made It Back Alive
Four astronauts splashed down in the Pacific Ocean on April 10, 2026, after traveling farther from Earth than any human beings in history. The Artemis II crew shattered a 56-year-old distance record set by Apollo 13, journeying nearly 253,000 miles from our planet during their 10-day lunar flyby mission. This marks the first time humans have ventured beyond low Earth orbit since 1972.

Amflow's Electric Bikes Are Blowing The Competition Away
Amflow, the e-bike brand spun out of DJI, has just released two impressive new electric mountain bikes that are breaking the mold with unprecedented power, range, and lightness. The flagship bikes are powered by the innovative Avinox motors and come with features like onboard navigation and heart rate control.

Canva Just Made a Power Play: Here's What It Means for the Future of Design and Marketing
Canva has made a bold move by acquiring two companies, Simtheory and Ortto, to boost its AI and marketing automation capabilities. This strategic move is set to revolutionize the way teams work on design and marketing projects. With these acquisitions, Canva is poised to become an all-in-one platform for businesses and individuals alike.

