EY Data Breach: Third-Party Support Ticket System Compromised

❓What:
EY disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information
EY uses a third-party IT service management platform to help its IT personnel support teams doing tax-related work for clients, and support tickets on that platform may include documents with client tax information
EY identified anomalous activity on the platform on April 23, 2026
Investigation with an outside cybersecurity firm determined that an unauthorized third party accessed the platform and downloaded documents on multiple EY clients between March 28 and April 12, 2026
No ransomware group has claimed the attack, and it's still unclear how many clients were affected
⚠️Impact:
Compromised information included certain personal and financial data contained in or used to prepare tax filings
EY says it's not currently aware of misuse of the exposed files or evidence that individuals were specifically targeted
Reputational exposure is real regardless: this is a Big Four firm — EY operates in 150+ countries with ~406,000 employees and about $53.2 billion in FY2025 revenue — with privileged access to sensitive client tax data, which makes any incident here high-profile
💡Recommendations:
EY has secured its systems, ended the unauthorized access, and notified federal authorities
Affected clients are being offered 24 months of identity monitoring and restoration services through Experian — enroll if you receive a notice
If you're an EY client, treat this as a prompt to review any tax documents shared via their support ticketing system and watch for phishing that references this incident
Given the third-party platform angle, worth asking your own vendors whether support-ticket systems store sensitive client docs unnecessarily, and whether retention/access controls on those tickets are tight
Read the full story HERE
