Ernst & Young (EY) has announced a significant data breach resulting from a compromise of a third-party support ticketing system utilized by its IT staff.
The breach potentially exposed support tickets that contained sensitive customer tax documents.
As one of the “Big Four” audit and professional services firms, EY provides audit, tax, consulting, and transaction advisory services to prominent organizations across over 150 countries.
With a workforce of 406,000 and global revenues reaching $53.2 billion in the last fiscal year, EY has a robust global presence.
The breach notification sent to affected clients indicated that unusual activity was detected on EY’s network on April 23, prompting an immediate investigation.
Working alongside external cybersecurity specialists, the company found that an unauthorized third party accessed the system and downloaded various documents between March 28 and April 12.
This breach may involve personal and financial data associated with tax return preparation. A sample notification can be accessed here, although the specific types of exposed data remain unspecified.
Moreover, the company has not disclosed the number of affected customers or if the breach extended beyond its U.S. client base.
Ernst & Young has stated that its systems have been secured, and federal law enforcement has been informed, ensuring unauthorized access is no longer a threat.
The firm has indicated it is unaware of any misuse of the stolen documents and there are currently no signs that specific individuals have been targeted by cybercriminals.
To mitigate risks associated with this breach, EY is providing affected clients with 24 months of identity monitoring and restoration services through Experian. Clients are urged to register for these services by October 31, 2026.
As of now, there are no indications that this incident is linked to any data extortion or ransomware groups.
BleepingComputer has reached out to EY for further clarification on the incident, but has not received a response at the time of publication.
Security teams document only 54% of successful attacks and issue a warning in just 14% of cases, while the remainder infiltrates unnoticed.
According to Picus’ latest whitepaper, organizations can proactively test their SIEM and EDR rules using breach and attack simulations to enhance threat detection.
Source: www.bleepingcomputer.com




