Ernst & Young (EY) disclosed a data breach after attackers gained unauthorized access to a third-party IT support and ticketing platform used by EY personnel supporting tax-related client work. EY said the intruders accessed the system between March 28 and April 12, 2026, downloaded multiple documents, and exposed personal and financial information used for tax preparation, including data tied to some individuals’ investment holdings with EY institutional clients. The firm detected anomalous activity on April 23, launched an investigation with external cybersecurity experts, secured affected systems, and notified federal law enforcement.
EY has not disclosed the identity of the third-party vendor, the number of affected individuals, the attack method, or any attribution to a threat actor. The company said it has not found evidence that the stolen information has been misused or that specific individuals were deliberately targeted, and began notifying affected people on July 13. EY also filed breach notifications with the California Attorney General and is offering eligible individuals 24 months of Experian identity monitoring and restoration services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
EY said affected clients would receive 24 months of identity monitoring and restoration services through Experian following the third-party support platform breach. The company also stated it had no evidence at the time that the exposed information had been misused or that specific individuals were targeted.
On July 15, 2026, EY filed breach notifications with the California Attorney General's office regarding the third-party support platform compromise.
EY began notifying affected individuals on July 13, 2026, stating that documents exposed in the incident contained personal and financial information tied to tax preparation and certain investment holdings.
On April 23, 2026, EY detected suspicious or anomalous activity involving the support platform, began investigating the incident, engaged external cybersecurity experts, secured its systems, and notified federal law enforcement.
An unauthorized party accessed a third-party IT support ticket platform used by EY personnel between March 28 and April 12, 2026, and downloaded documents containing personal and financial information used for tax preparation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecyberveille.ch
Open sourcethecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcethecybersecguru.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.