News·3 min read

Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents

Ernst & Young LLP, one of the world’s Big Four professional services firms, has disclosed a data breach in which an unauthorized third party infiltrated a vendor-managed IT service platform

CS
CyberShield Team
2026-07-18
Share:
Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents

Ernst & Young LLP, one of the world’s Big Four professional services firms, has disclosed a data breach in which an unauthorized third party infiltrated a vendor-managed IT service platform and exfiltrated documents containing client tax data. The firm filed formal breach notifications with the California Attorney General’s office on July 15, 2026, and with […] The post Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents appeared first on Cyber Security News.

Ernst & Young LLP, one of the world’s Big Four professional services firms, has disclosed a data breach in which an unauthorized third party infiltrated a vendor-managed IT service platform and exfiltrated documents containing client tax data. The firm filed formal breach notifications with the California Attorney General’s office on July 15, 2026, and with Vermont regulators the following day, confirming the incident’s scope to affected clients nationwide. EY relies on a third-party IT service management platform that its internal information technology personnel use to support teams performing tax-related engagements for clients. EY Data Breach Support tickets logged through this system frequently included attached documents containing sensitive client tax information, making the platform a high-value target. EY first flagged anomalous activity within the platform on April 23, 2026, prompting the immediate activation of its incident response procedures. Working with an independent cybersecurity firm, EY later revealed in its investigation that the actual intrusion window predated detection by nearly a month. The unauthorized party had accessed the platform and downloaded documents between March 28, 2026, and April 12, 2026, giving attackers roughly two weeks of undetected access before the breach was even identified. That detection lag of about three weeks gave the threat actor a substantial opportunity to exfiltrate data pertaining to numerous EY clients. The stolen documents contained personal information tied to individuals’ investment holdings maintained with EY’s institutional clients, along with financial data used to prepare tax filings. A separate filing with the Vermont Attorney General’s office indicated the exposure may have included Social Security numbers, financial account codes, and credit or debit account information. EY’s notification letters to affected individuals use placeholder data-element fields, suggesting the specific categories of exposed data vary by recipient and business unit. EY says it has contained the incident, confirming that unauthorized access to the platform has been stopped and that its systems have been secured. The firm notified federal law enforcement and continues monitoring for signs that the stolen information has surfaced elsewhere. EY states it currently has no evidence of misuse of the exposed data and no indication that specific individuals were deliberately targeted. To mitigate downstream risk, EY is offering affected individuals 24 months of complimentary credit and identity monitoring through Experian IdentityWorks, along with Identity Restoration services, with an enrollment deadline of October 31, 2026. As of this writing, no ransomware or data-extortion group has publicly claimed responsibility for the intrusion, and the identity of the threat actor remains undisclosed. The incident underscores persistent third-party risk exposure among large professional services firms, coming roughly nine months after EY separately disclosed an unrelated 4TB cloud storage misconfiguration tied to its Italy branch. The EY case adds to a growing list of 2026 breaches originating not from a firm’s core network, but from vendor-managed IT ticketing and support infrastructure a vector increasingly favored by attackers seeking indirect access to sensitive client data. Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs The post Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.