Hackers Breach EY Support System, Exposing Client Tax Records
Share
Ernst & Young (EY) Confirms Data Breach After Hackers Access Clients’ Tax Documents
- EY Confirms Data Breach After Hackers Access Sensitive Tax Documents
- Millions Could Be at Risk as EY Reveals Tax Data Security Incident
- Hackers Breach EY Support System, Exposing Client Tax Records
- EY Data Breach Raises Fears Over Stolen Financial and Tax Information
- Cyberattack Hits EY, Putting Confidential Client Tax Documents at Risk
- EY Warns Clients After Hackers Access Third-Party Tax Support Platform
Global consulting and accounting giant Ernst & Young (EY) has disclosed a data breach after cybercriminals gained unauthorized access to a third-party support platform used to assist employees handling client tax services, potentially exposing sensitive financial and personal information.
The incident has raised fresh concerns about the growing cybersecurity risks facing professional services firms that manage highly confidential client records, including tax documents, financial data, and personally identifiable information.
Hackers Breached Third-Party Support System
According to notifications sent to affected individuals, the attackers compromised an external IT service management platform used by EY’s tax support teams. The unauthorized access reportedly occurred between March 28 and April 12, 2026, during which attackers downloaded documents stored within support tickets.
Because employees often attached client files while seeking technical assistance, the compromised documents may contain sensitive tax-related information.
What Information May Have Been Exposed?
EY says the exposed files may include personal and financial information submitted as part of tax support requests.
Depending on the individual case, the affected documents could contain:
- Full names
- Home addresses
- Tax records
- Financial information
- Government-issued identification details
- Other personally identifiable information included in support documents
The company has not disclosed the total number of people affected, but regulatory filings indicate the investigation remains ongoing.
EY Takes Action After Discovering the Breach
EY says it immediately terminated the unauthorized access after identifying the incident, secured the affected systems, launched a forensic investigation, and notified law enforcement.
The firm is also offering complimentary identity protection and credit monitoring services to affected individuals while continuing to review the full scope of the breach.
Why This Breach Matters
Accounting and consulting firms have become increasingly attractive targets for cybercriminals because they store enormous amounts of sensitive financial and tax information belonging to businesses, executives, and individual clients.
Unlike traditional consumer data breaches, attacks involving tax records can expose information valuable for identity theft, tax fraud, phishing campaigns, and financial scams.
Security experts warn that criminals frequently use stolen tax documents to impersonate victims, file fraudulent tax returns, or craft convincing social engineering attacks.
What Clients Should Do Now
Individuals who may have worked with EY on tax-related services are encouraged to remain vigilant by:
- Monitoring financial and tax accounts for unusual activity.
- Watching for unexpected emails or phone calls requesting personal information.
- Changing passwords if similar credentials are used elsewhere.
- Taking advantage of any identity monitoring services offered by EY.
- Reporting suspected fraud immediately to financial institutions and relevant authorities.
Growing Pressure on Third-Party Security
The incident also highlights a growing challenge facing organizations worldwide: securing third-party vendors that process or store sensitive information.
Even companies with mature cybersecurity programs remain vulnerable when external service providers become attack vectors. As businesses increasingly rely on cloud-based support platforms, regulators and cybersecurity experts are calling for stronger oversight of third-party systems that handle confidential customer data.
The EY breach serves as another reminder that protecting sensitive information requires securing not only internal networks but also every external partner that has access to critical business and customer data.




Leave a Reply