LIVE · cybersecurity feed
Live wire
data breachhigh

Ernst & Young Data Breach Linked to Compromised Third-Party Support System

Ernst & Young (EY) has reported a data breach stemming from a compromised third-party IT support ticket system. The attackers gained access to documents containing client tax information that were stored within the platform. EY detected suspicious activity on April 23rd and has engaged cybersecurity experts to investigate the incident, confirming that unauthorized access has ceased.

zeroday.news · 15d ago

Ernst & Young (EY), one of the "Big Four" professional services firms, has disclosed a data breach stemming from the compromise of a third-party IT support system. The incident, which EY detected on April 23, 2026, involved unauthorized access to a platform used by its IT teams to manage support requests for tax-related work.

The firm's investigation, conducted with the assistance of an independent cybersecurity firm, determined that an unauthorized party accessed the platform between March 28, 2026, and April 12, 2026. During this period, the attackers downloaded documents pertaining to a number of EY clients. These documents may have contained sensitive personal and financial information used in the preparation of tax filings.

EY confirmed that it has secured its systems and eliminated the unauthorized access. The company has also notified federal authorities about the breach. While the full extent of the impact on clients is still being assessed, EY is offering 24 months of identity monitoring and restoration services through Experian to affected individuals.

According to EY, there is currently no evidence to suggest that the exposed files have been misused or that specific individuals were targeted in the attack. No ransomware group has publicly claimed responsibility for the incident.

EY operates globally in over 150 countries, employing approximately 406,000 individuals, and reported global revenues of about $53.2 billion in fiscal year 2025. Its extensive access to sensitive client data makes it a significant target for cybercriminals.

data breachthird-party risktax informationcybersecurity incident
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]