Key Takeaways

- Attackers accessed EY's third-party support ticket system for roughly two weeks, stealing tax-related client data
- EY is offering affected clients 24 months of free Experian IdentityWorks and Identity Restoration services
- Victims should consider freezing their credit and signing up for an IRS identity protection PIN before October 31, 2026
Ernst & Young has disclosed a data breach that gave attackers access to client tax information for roughly two weeks. The breach, which occurred between March 28 and April 12, targeted a third-party support ticket system the Big Four accounting firm uses to handle tax work. EY filed breach notices with California, Massachusetts, and Vermont on July 15 and has begun notifying affected clients.

How did the Ernst & Young breach happen?
The intrusion hit a third-party IT platform that EY teams use to submit support tickets. Those tickets often contain sensitive customer data related to tax filings. For two weeks, the attacker downloaded records "pertaining to a number of EY clients," according to the company's notice.
EY detected suspicious activity on April 23, more than a week after the unauthorized access ended. The firm hired an outside cybersecurity company to investigate. The support ticket system has since been secured, but EY hasn't disclosed whether malware was involved or identified the responsible party.
This pattern, a vendor breach exposing client data, has become the dominant attack vector for sophisticated threat actors. Going after service providers like accounting firms gives attackers access to hundreds or thousands of downstream targets in a single compromise.
Another major 2026 data breach that exposed millions of user records
What data was stolen?
EY's notification letter references "certain financial information contained in or used to prepare tax filings." The firm hasn't disclosed the full list of data types, but tax filings typically require names, addresses, Social Security numbers, and financial account details. Each victim's letter should list their specific exposed data points.
The company states it is "not aware of any misuse or further exposure" of personal information and says there's no "indication [your] personal information was specifically targeted." That's standard breach disclosure language, not a guarantee. Tax data is valuable precisely because it contains everything needed for identity theft and fraudulent tax filings.
How do I know if I'm affected?
If you're an EY tax client, watch your mail. The firm is sending letters to affected individuals that detail exactly what information was stolen. EY hasn't disclosed how many clients were hit, so the notification rollout may take time. Not receiving a letter yet doesn't mean you're safe.
EY is offering two free Experian services for 24 months: IdentityWorks (credit monitoring) and Identity Restoration. You'll need the code in your letter to activate these services before October 31, 2026. That deadline is firm.
What should affected clients do now?
- Activate the free Experian services using your letter's code before the October 31, 2026 deadline
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) until the scope of the breach is clearer
- Sign up for an IRS Identity Protection PIN to prevent anyone from filing taxes using your Social Security number
- Monitor your bank accounts and credit card statements for unauthorized transactions
- Request your free annual credit reports and check for accounts you didn't open
The IRS identity protection PIN is the most important step if your Social Security number was exposed. It blocks anyone from filing a federal tax return in your name without the PIN, which is the primary risk when tax data leaks.
How AI is being deployed to find and fix security vulnerabilities
Why third-party breaches keep happening
This breach follows a familiar script. Large enterprises outsource functions to vendors, those vendors handle sensitive data, and attackers target the vendor as the weakest link. A support ticket system might seem low-priority, but any system that touches customer data is a target.
The gap between the breach end date (April 12) and EY's detection (April 23) shows how hard it is to spot intrusions in third-party systems. Companies often lack visibility into vendor security controls, and vendors may not have the monitoring capabilities of their larger clients.
Logicity's Take
For CTOs and security leaders, this breach is a reminder to audit your vendor ecosystem aggressively. Ask your vendors: How do you monitor for unauthorized access? What's your mean time to detect an intrusion? The two-week dwell time here is troubling but not unusual. Companies handling tax data or other sensitive records should require vendors to meet specific detection and response benchmarks, not just check compliance boxes. The real risk isn't EY itself. It's every third-party tool in your stack that touches customer data.
New security feature designed to detect unauthorized access
Frequently Asked Questions
How long did attackers have access to EY's system?
Attackers had access to the third-party support ticket system from March 28 to April 12, roughly two weeks. EY detected the suspicious activity on April 23.
What should I do if I received an EY breach notification letter?
Activate the free Experian IdentityWorks and Identity Restoration services using your letter's code before October 31, 2026. Consider freezing your credit and signing up for an IRS identity protection PIN.
Is my Social Security number at risk from the EY breach?
EY hasn't disclosed the specific data types stolen. However, tax filings typically require Social Security numbers, so it's possible. Your notification letter should list your specific exposed data.
How do I sign up for an IRS identity protection PIN?
Visit the IRS website and use their Get an IP PIN tool. This prevents anyone from filing a federal tax return using your Social Security number without your unique PIN.
Did EY disclose how many clients were affected?
No. EY has not disclosed the total number of affected clients. Breach notices were filed in California, Massachusetts, and Vermont, but the full scope remains unknown.
Need Help Implementing This?
If your organization needs to strengthen vendor security assessments or incident response capabilities, Logicity can connect you with cybersecurity consultants who specialize in third-party risk management. Contact us for recommendations.
Source: Latest news
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
AI Revolution: How Tech is Transforming the World, One Industry at a Time
From desalination plants in Iran to AI-powered manufacturing, the tech world is abuzz with innovation. Discover how AI is changing the game for small entrepreneurs and what it means for the future of industry. Explore the latest developments in cybersecurity, robotics, and more.

Revolutionizing AI: The Game-Changing Tech That's Making Agents Smarter
A new technology is set to revolutionize the way AI agents learn and adapt, enabling them to accumulate wisdom and apply it to new situations. This innovation has the potential to significantly boost the reliability of AI agents, especially in complex tasks. By converting raw agent trajectories into reusable guidelines, this tech is poised to transform the AI landscape.

The Dark Side of AI: How Bots Are Fueling a Monetized Abuse Ecosystem
A recent analysis of 2.8 million Telegram messages reveals a shocking truth: AI-powered bots are being used to create and sell non-consensual intimate images. These bots can turn ordinary photos into synthetic nude images, and the abuse is being monetized through affiliate programs and subscription-based archives. The researchers behind the study are calling for stricter regulations to combat this growing problem.

AI's Secret Sauce: How Journalism Became the Unlikely Ingredient
A recent study reveals that AI chatbots rely heavily on journalistic sources for their quotes, with one in four coming from news outlets. This shocking discovery has significant implications for the media industry and our understanding of AI's information gathering processes. As AI technology continues to evolve, it's essential to consider the role of journalism in shaping its responses.


