CSIDB logo
Incident

Ernst & Young

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 00:14

Linked entities

Victim
Ernst & Young
Threat actors
1 actor
Sources
7 sources

Timeline

Occurred
Mar 2026
Discovered
Apr 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

Ernst & Young disclosed a breach involving a third‑party IT support platform that was accessed without authorization, allowing attackers to download client tax and financial documents. The intrusion was detected after the access window closed, and the firm delayed notifying affected individuals while offering identity‑monitoring services. An extortion group later claimed responsibility and threatened to release the stolen data unless contacted.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Ernst & Young detected anomalous activity within a third‑party information technology service management platform on April 23, 2026, after an unauthorized party had accessed the system between March 28 and April 12 of that year. The intrusion lasted approximately fifteen days during which threat actors downloaded documents attached to support tickets used by EY’s IT personnel to assist tax‑related work for clients. Upon detection, EY’s information security team initiated its incident response procedure, engaged an independent cybersecurity firm to investigate, contained the breach and confirmed that the unauthorized access had been stopped. The firm subsequently filed a breach notice with the California Attorney General’s office on July 15, 2026, having sent notification letters to affected individuals dated July 13, 2026, reflecting an eighty‑one‑day gap between detection and public disclosure.

The compromised platform stored support tickets that often included attachments containing client tax information, and the exposed data comprised names, addresses, Social Security numbers, bank account details, payment card numbers, investment holdings and other financial records used to prepare tax filings. While EY has not released a total count of affected individuals, state‑level filings indicate at least 1,366 California residents were impacted, with notices also sent to the attorneys general of Texas, Massachusetts and Vermont. The company has stated that the breach was confined to the third‑party support system and that no evidence of further misuse or targeted attacks against specific individuals has been found. EY has offered twenty‑four months of free credit monitoring, identity monitoring and identity restoration services through Experian to those whose data was exposed.

ShinyHunters, a known extortion group, claimed responsibility for the intrusion in posts on a Tor‑based leak site and threatened to publish the stolen data unless negotiations began by July 31, 2026, a claim referenced in multiple security news outlets. Other sources, however, note that no ransomware or extortion group has been publicly confirmed as the attacker and that EY has not attributed the incident to any specific threat actor. Regardless of attribution, EY reported that it had worked with federal law enforcement, secured its systems and completed remediation efforts. The firm also confirmed that it had not observed any misuse of the exposed information subsequent to the breach.

The delay between detection and notification has drawn criticism from privacy attorneys and has become a focal point in media coverage of the incident, with the eighty‑one‑day interval cited as a potential basis for class‑action filings. The breach has added EY to the list of major professional services firms that have experienced vendor‑related compromises, highlighting the risks associated with third‑party IT support platforms that store sensitive client attachments. Regulatory scrutiny has followed, with state attorneys general reviewing the firm’s handling of the incident and the adequacy of its notification timeline. The incident remains under investigation, and EY continues to provide the offered identity protection services to affected individuals.

Sources

Sources available to members: 7 sources.

CSIDB