Ernst & Young
Incident posture
Linked entities
- Victim
- Ernst & Young
- Threat actors
- 1 actor
- Sources
- 7 sources
Timeline
Summary
Ernst & Young disclosed a breach involving a third‑party IT support platform that was accessed without authorization, allowing attackers to download client tax and financial documents. The intrusion was detected after the access window closed, and the firm delayed notifying affected individuals while offering identity‑monitoring services. An extortion group later claimed responsibility and threatened to release the stolen data unless contacted.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Ernst & Young detected anomalous activity within a third‑party information technology service management platform on April 23, 2026, after an unauthorized party had accessed the system between March 28 and April 12 of that year. The intrusion lasted approximately fifteen days during which threat actors downloaded documents attached to support tickets used by EY’s IT personnel to assist tax‑related work for clients. Upon detection, EY’s information security team initiated its incident response procedure, engaged an independent cybersecurity firm to investigate, contained the breach and confirmed that the unauthorized access had been stopped. The firm subsequently filed a breach notice with the California Attorney General’s office on July 15, 2026, having sent notification letters to affected individuals dated July 13, 2026, reflecting an eighty‑one‑day gap between detection and public disclosure.
The compromised platform stored support tickets that often included attachments containing client tax information, and the exposed data comprised names, addresses, Social Security numbers, bank account details, payment card numbers, investment holdings and other financial records used to prepare tax filings. While EY has not released a total count of affected individuals, state‑level filings indicate at least 1,366 California residents were impacted, with notices also sent to the attorneys general of Texas, Massachusetts and Vermont. The company has stated that the breach was confined to the third‑party support system and that no evidence of further misuse or targeted attacks against specific individuals has been found. EY has offered twenty‑four months of free credit monitoring, identity monitoring and identity restoration services through Experian to those whose data was exposed.
ShinyHunters, a known extortion group, claimed responsibility for the intrusion in posts on a Tor‑based leak site and threatened to publish the stolen data unless negotiations began by July 31, 2026, a claim referenced in multiple security news outlets. Other sources, however, note that no ransomware or extortion group has been publicly confirmed as the attacker and that EY has not attributed the incident to any specific threat actor. Regardless of attribution, EY reported that it had worked with federal law enforcement, secured its systems and completed remediation efforts. The firm also confirmed that it had not observed any misuse of the exposed information subsequent to the breach.
The delay between detection and notification has drawn criticism from privacy attorneys and has become a focal point in media coverage of the incident, with the eighty‑one‑day interval cited as a potential basis for class‑action filings. The breach has added EY to the list of major professional services firms that have experienced vendor‑related compromises, highlighting the risks associated with third‑party IT support platforms that store sensitive client attachments. Regulatory scrutiny has followed, with state attorneys general reviewing the firm’s handling of the incident and the adequacy of its notification timeline. The incident remains under investigation, and EY continues to provide the offered identity protection services to affected individuals.
Sources
Sources available to members: 7 sources.