Ernst & Young says hackers accessed a third-party support system and stole documents that may include client tax data

Ernst & Young says an attacker got into a third-party support ticket system used by its IT staff and downloaded documents that may contain client tax information. EY says the unauthorized access lasted from March 28 to April 12, 2026, and was discovered after anomalous activity on April 23. Exposed data may include personal and financial information contained in or used to prepare tax filings, though EY has not disclosed how many clients were affected or whether the breach extends beyond the U.S.
Why it matters: Clients whose tax documents were submitted through EY support tickets could face identity or financial fraud risks, so affected recipients should review the notice, enroll in monitoring, and watch tax and financial accounts closely. For defenders, the case highlights third-party support platforms as a sensitive data exposure point that needs tighter access controls and review.

Sources

Ernst & Young discloses data breach after support system hack
Bill Toulas 2026.07.17 100% relevant
This article appears to be the first disclosure of EY's breach of a third-party support ticket platform exposing tax-related client documents, and it does not match an existing tracked story.
← Back to all stories