Ernst & Young (EY), one of the world's Big Four professional services firms, is notifying clients of a data breach stemming from the compromise of a third-party IT support ticket system used by its IT personnel to assist teams performing tax-related client work.
EY says it identified anomalous activity within the platform on April 23, 2026, and immediately launched an incident response investigation. Working with an independent cybersecurity firm, EY determined that between March 28 and April 12, 2026, an unauthorized third party accessed the platform and downloaded documents pertaining to a number of EY clients. Notification letters, dated July 13, were sent via U.S. Mail and email as the firm began alerting affected individuals in July.
The exposed data extends beyond EY's direct clients. Because EY performs tax work for financial institutions, the affected individuals in several cases may not have had a direct relationship with EY at all, their personal data was provided to EY by financial institutions in connection with investment-related tax work. According to notification letters, exposed information included names, addresses, dates of birth, Social Security numbers, driver's license numbers, email addresses, and phone numbers.
State filings offer a partial scope: 873 Texas residents, 480 Massachusetts residents, and 13 Vermont residents were affected, though EY has not disclosed the total number impacted, which third-party vendor was compromised, or whether the breach extends beyond its U.S. client base.
EY says its core internal systems were not compromised, the vulnerability sat within a third-party vendor's support infrastructure rather than EY's primary platforms. The firm has secured its systems, notified federal law enforcement, and reports no evidence of data misuse, further exposure, or targeting of specific individuals. No ransomware or extortion group has claimed responsibility.
Affected clients are being offered 24 months of identity monitoring and restoration services through Experian, with an enrollment deadline of October 31, 2026. Separately, at least one law firm, Edelson Lechtzin LLP, has announced it is investigating potential class action claims on behalf of affected individuals.
With roughly 406,000 employees and $53.2 billion in fiscal 2025 revenue across 150+ countries, EY's scale underscores a recurring pattern in enterprise security: the breach didn't originate in EY's own systems, but in a third-party vendor's infrastructure, the same vendor-concentration risk that's become a central theme across this year's identity and data-security incidents.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




