Menu
Browse

Cyber Incident Victim: Ernst & Young

Date:

Mar 2026

Location:

United States of America

Summary

Ernst & Young discovered a data breach linked to a compromised third‑party support ticket system used by its IT teams. The firm detected anomalous activity, launched an investigation with external experts, and determined that an unauthorized party accessed the platform and downloaded documents that may have contained client tax information, including personal and financial data. The number of affected clients is not yet known. The firm secured its systems, removed the unauthorized access, notified federal authorities, and is providing affected clients with identity monitoring services; it has stated there is no evidence of misuse of the exposed data and no ransomware group has claimed responsibility.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 23, 2026, Ernst & Young identified anomalous activity within a third‑party information technology service management platform used by its IT teams to handle support tickets. The platform, which stores support requests that may have included documents containing client tax information, was accessed by an unauthorized third party between March 28 and April 12, 2026. During that window the intruder downloaded multiple documents pertaining to a number of EY clients. EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts.

Cyber Incident Image

Working with an independent cybersecurity firm, EY confirmed that the unauthorized access had been stopped and that its systems were now secure. The compromised information consisted of certain personal and financial data contained in or used to prepare tax filings. At the time of disclosure, it remained unclear how many customers were affected by the breach. EY stated that it had no evidence of misuse of the exposed files or any indication that the personal information was specifically targeted.

EY announced that it had secured its systems, removed the unauthorized access, and notified federal authorities. To assist affected clients, the firm is offering 24 months of identity monitoring and restoration services through Experian. EY also noted that it is providing information about steps individuals can take to further secure their personal information. As of the announcement, no ransomware group had claimed responsibility for the attack.

Sources
Sources available to members
3 sources