Ernst & Young (EY), one of the "Big Four" professional services firms, has disclosed a data breach stemming from the compromise of a third-party IT support system. The incident, which EY detected on April 23, 2026, involved unauthorized access to a platform used by its IT teams to manage support requests for tax-related work.
The firm's investigation, conducted with the assistance of an independent cybersecurity firm, determined that an unauthorized party accessed the platform between March 28, 2026, and April 12, 2026. During this period, the attackers downloaded documents pertaining to a number of EY clients. These documents may have contained sensitive personal and financial information used in the preparation of tax filings.
EY confirmed that it has secured its systems and eliminated the unauthorized access. The company has also notified federal authorities about the breach. While the full extent of the impact on clients is still being assessed, EY is offering 24 months of identity monitoring and restoration services through Experian to affected individuals.
According to EY, there is currently no evidence to suggest that the exposed files have been misused or that specific individuals were targeted in the attack. No ransomware group has publicly claimed responsibility for the incident.
EY operates globally in over 150 countries, employing approximately 406,000 individuals, and reported global revenues of about $53.2 billion in fiscal year 2025. Its extensive access to sensitive client data makes it a significant target for cybercriminals.






