395/69 Monday, July 20, 2026

Ernst & Young (EY) has disclosed a data breach after a third-party support ticket system used by the company’s IT personnel was accessed without authorization. Tickets submitted through the system may have contained documents that included clients’ tax information. EY is one of the world’s largest accounting firms, providing audit, tax, consulting, and transaction advisory services to large organizations in more than 150 countries.
According to a notification letter sent to affected clients, EY detected suspicious activity on its network on April 23, 2026, and began an investigation with external cybersecurity experts. The investigation found that an unauthorized third party accessed the platform between March 28 and April 12, 2026, and downloaded multiple documents. The affected information may include some personal and financial information contained in the documents or used to prepare tax filings. However, EY has not clearly specified the types of data exposed, the number of affected clients, or whether the incident affected only clients in the United States or also included clients in other countries.
EY stated that it has secured the system and confirmed that the unauthorized access has been terminated. The company has also reported the incident to federal law enforcement authorities. EY said it has found no evidence that the stolen information has been misused or further disclosed, and there is no indication that the attackers targeted any specific individual. To reduce the risk from this incident, EY is offering affected clients 24 months of complimentary identity monitoring and identity restoration services through Experian. The company also advised individuals who received notification letters to enroll by October 31, 2026. At the time of reporting, no data extortion or ransomware group had claimed responsibility for the incident.
