Professional services firm Ernst & Young reports a data breach. Attackers gained access to tax documents through an IT support system.
Professional services and accounting firm Ernst & Young (EY) is informing its customers about a data security incident. An unauthorized third party gained access to an IT service management platform operated by an external service provider for the company’s IT personnel. The unauthorized access occurred between March 28 and April 12, 2026. During this period, several documents were downloaded from the platform. The company described the technical context in the notification letter sent to those affected:
“EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.”
Ernst & Young
Affected customer data and company scale
The exfiltrated files contain personal and financial data used to prepare or contained within tax filings. The exact categories of affected data vary depending on the recipient and are specified in the individual notification letters. Ernst & Young has not provided precise details regarding the total number of customers affected by the data breach. It also remains unclear whether the incident is limited exclusively to customers in the US or if it affects other countries as well. Ernst & Young employs around 406,000 people worldwide and generated a global revenue of 53.2 billion US dollars in the past fiscal year.
Security measures and identity protection for affected individuals
Following the detection of the anomalous activity on April 23, 2026, the internal information security team launched an investigation and brought in an independent cybersecurity firm. According to the company, the unauthorized access has been terminated and the systems have been secured. US federal law enforcement authorities have been notified of the incident.
Ernst & Young stated that it currently has no evidence that the stolen data has been misused or further distributed. At this stage, no ransomware or extortion group has claimed responsibility for the attack. As a protective measure, the company is offering affected customers free identity monitoring services for a period of 24 months through the service provider Experian. Registration for this service must be completed by October 31, 2026.
(red)