All posts

Ernst & Young breach exposed client tax data for two weeks

Manaal KhanJuly 25, 2026 at 11:01 AM5 min read
Ernst & Young breach exposed client tax data for two weeks

Key Takeaways

Ernst & Young breach exposed client tax data for two weeks
Source: Latest news
  • Attackers accessed EY's third-party support ticket system for roughly two weeks, stealing tax-related client data
  • EY is offering affected clients 24 months of free Experian IdentityWorks and Identity Restoration services
  • Victims should consider freezing their credit and signing up for an IRS identity protection PIN before October 31, 2026

Ernst & Young has disclosed a data breach that gave attackers access to client tax information for roughly two weeks. The breach, which occurred between March 28 and April 12, targeted a third-party support ticket system the Big Four accounting firm uses to handle tax work. EY filed breach notices with California, Massachusetts, and Vermont on July 15 and has begun notifying affected clients.

Image (Source: Latest news)
Image (Source: Latest news)
Advertisements

How did the Ernst & Young breach happen?

The intrusion hit a third-party IT platform that EY teams use to submit support tickets. Those tickets often contain sensitive customer data related to tax filings. For two weeks, the attacker downloaded records "pertaining to a number of EY clients," according to the company's notice.

EY detected suspicious activity on April 23, more than a week after the unauthorized access ended. The firm hired an outside cybersecurity company to investigate. The support ticket system has since been secured, but EY hasn't disclosed whether malware was involved or identified the responsible party.

This pattern, a vendor breach exposing client data, has become the dominant attack vector for sophisticated threat actors. Going after service providers like accounting firms gives attackers access to hundreds or thousands of downstream targets in a single compromise.

Also Read
Suno breach exposed 55M users' data, source code stolen

Another major 2026 data breach that exposed millions of user records

What data was stolen?

EY's notification letter references "certain financial information contained in or used to prepare tax filings." The firm hasn't disclosed the full list of data types, but tax filings typically require names, addresses, Social Security numbers, and financial account details. Each victim's letter should list their specific exposed data points.

The company states it is "not aware of any misuse or further exposure" of personal information and says there's no "indication [your] personal information was specifically targeted." That's standard breach disclosure language, not a guarantee. Tax data is valuable precisely because it contains everything needed for identity theft and fraudulent tax filings.

How do I know if I'm affected?

If you're an EY tax client, watch your mail. The firm is sending letters to affected individuals that detail exactly what information was stolen. EY hasn't disclosed how many clients were hit, so the notification rollout may take time. Not receiving a letter yet doesn't mean you're safe.

EY is offering two free Experian services for 24 months: IdentityWorks (credit monitoring) and Identity Restoration. You'll need the code in your letter to activate these services before October 31, 2026. That deadline is firm.

Advertisements

What should affected clients do now?

  1. Activate the free Experian services using your letter's code before the October 31, 2026 deadline
  2. Freeze your credit at all three bureaus (Equifax, Experian, TransUnion) until the scope of the breach is clearer
  3. Sign up for an IRS Identity Protection PIN to prevent anyone from filing taxes using your Social Security number
  4. Monitor your bank accounts and credit card statements for unauthorized transactions
  5. Request your free annual credit reports and check for accounts you didn't open

The IRS identity protection PIN is the most important step if your Social Security number was exposed. It blocks anyone from filing a federal tax return in your name without the PIN, which is the primary risk when tax data leaks.

Also Read
Google CodeMender scans and fixes code vulnerabilities via AI

How AI is being deployed to find and fix security vulnerabilities

Why third-party breaches keep happening

This breach follows a familiar script. Large enterprises outsource functions to vendors, those vendors handle sensitive data, and attackers target the vendor as the weakest link. A support ticket system might seem low-priority, but any system that touches customer data is a target.

The gap between the breach end date (April 12) and EY's detection (April 23) shows how hard it is to spot intrusions in third-party systems. Companies often lack visibility into vendor security controls, and vendors may not have the monitoring capabilities of their larger clients.

ℹ️

Logicity's Take

For CTOs and security leaders, this breach is a reminder to audit your vendor ecosystem aggressively. Ask your vendors: How do you monitor for unauthorized access? What's your mean time to detect an intrusion? The two-week dwell time here is troubling but not unusual. Companies handling tax data or other sensitive records should require vendors to meet specific detection and response benchmarks, not just check compliance boxes. The real risk isn't EY itself. It's every third-party tool in your stack that touches customer data.

Also Read
Android 17's Intrusion Logging tracks suspicious app behavior

New security feature designed to detect unauthorized access

Frequently Asked Questions

How long did attackers have access to EY's system?

Attackers had access to the third-party support ticket system from March 28 to April 12, roughly two weeks. EY detected the suspicious activity on April 23.

What should I do if I received an EY breach notification letter?

Activate the free Experian IdentityWorks and Identity Restoration services using your letter's code before October 31, 2026. Consider freezing your credit and signing up for an IRS identity protection PIN.

Is my Social Security number at risk from the EY breach?

EY hasn't disclosed the specific data types stolen. However, tax filings typically require Social Security numbers, so it's possible. Your notification letter should list your specific exposed data.

How do I sign up for an IRS identity protection PIN?

Visit the IRS website and use their Get an IP PIN tool. This prevents anyone from filing a federal tax return using your Social Security number without your unique PIN.

Did EY disclose how many clients were affected?

No. EY has not disclosed the total number of affected clients. Breach notices were filed in California, Massachusetts, and Vermont, but the full scope remains unknown.

ℹ️

Need Help Implementing This?

If your organization needs to strengthen vendor security assessments or incident response capabilities, Logicity can connect you with cybersecurity consultants who specialize in third-party risk management. Contact us for recommendations.

Source: Latest news

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.

Related Articles