Ernst & Young (EY) has begun notifying clients of a data breach stemming from unauthorized access to a third-party support ticket system utilized by its IT department. The professional services giant, one of the world's largest, discovered unusual activity on its networks on April 23 and launched an investigation with external cybersecurity specialists.
The investigation revealed that an unauthorized party gained access to the support platform between March 28 and April 12, during which time multiple documents were downloaded. These documents, according to EY, may have contained client tax information, including personal and financial data used in the preparation of tax filings.
While the specific types of data exposed were not detailed in the provided notification sample, EY confirmed that the compromised information related to tax preparation. The company has not disclosed the total number of affected clients or whether the incident extends beyond its U.S. customer base to other countries where it operates.
EY, which employs 406,000 people globally and reported $53.2 billion in revenue last year, stated that it has secured its systems and eliminated the unauthorized access. Federal law enforcement authorities have been notified of the incident.
The firm has indicated that it is not aware of any misuse or further exposure of the stolen files and has no evidence that specific individuals were targeted by the threat actors. To help mitigate potential risks for affected clients, EY is offering 24 months of identity monitoring and restoration services through Experian, advising recipients of the breach notification to enroll by October 31, 2026.
As of the current reporting, no data extortion or ransomware groups have publicly claimed responsibility for the attack on Ernst & Young.






