Ernst & Young, one of the Big Four accounting firms trusted with the financial secrets of millions, just confirmed that attackers spent roughly two weeks rifling through a third-party system used for client tax services. The breach window ran from March 28 to April 12, 2026, but EY didn’t detect it until April 23. Clients didn’t start receiving notifications until July.
What happened and what was exposed
The breach targeted an external IT support platform that EY used to handle client tax filings. Attackers gained unauthorized access and downloaded documents that contained personal and financial information tied to tax records. The compromised data potentially includes Social Security numbers.
EY brought in an independent cybersecurity firm to investigate the incident after discovering the unauthorized access. The company says it has since shut down the attack vector and secured its systems.
EY’s core internal systems were not compromised, according to the firm’s own assessment. The vulnerability existed in a third-party vendor’s support ticket infrastructure, not in EY’s primary platforms.










