Particle.news
Download on the App Store

Ernst & Young Breach Exposes Client Tax Records From Third‑Party Support Platform

The disclosure signals higher fraud risk for clients.

Overview

  • Ernst & Young says an unauthorized actor accessed a third‑party IT service management/support ticket platform and downloaded client documents between March 28 and April 12, 2026.
  • The stolen files may include personal and financial data used for tax filings such as names, addresses, Social Security numbers, bank account numbers, and card details.
  • EY detected anomalous activity on April 23, 2026, removed the unauthorized access, engaged external cybersecurity investigators, and began notifying affected clients in July while offering 24 months of Experian identity and credit monitoring.
  • Key facts remain unknown: EY has not named the third‑party vendor, has not disclosed how many clients were affected or whether non‑U.S. clients were involved, and no extortion claim or public posting of the data has been observed.
  • Multiple law firms have opened investigations into class‑action claims and the incident highlights broader supply‑chain risk for firms that rely on external support platforms and the elevated potential for tax‑related identity fraud.