EY Security Breach Exposes Tax Documents
A compromised third-party support platform has led to the exposure of client tax files at professional services giant Ernst & Young.
Ernst & Young, one of the world's largest professional services organizations, is working to address the fallout from a security incident involving its IT support infrastructure. The breach centers on a third-party ticket management platform, which attackers utilized to gain unauthorized access to internal documentation.
As a global entity, Ernst & Young operates across more than 150 countries, providing a wide array of auditing and tax advisory services. The firm currently maintains a massive global footprint, employing a workforce of 406,000 people to support its operations.
Unauthorized Access to Support Platform
The company first identified signs of irregular behavior on its network on April 23. Upon launching an investigation alongside external cybersecurity specialists, the firm discovered that an unauthorized actor had infiltrated a specific support ticket system. This unauthorized access occurred during a window spanning March 28 and April 12, during which the adversary successfully downloaded several documents.
Scope of the Exposed Data
The files potentially compromised through this platform include sensitive financial and personal data linked to client tax filings. While the firm has confirmed that documents were accessed, the precise nature of the personal information remains unspecified as the provided notification documentation contains placeholders for exact data types.
The organization has not yet disclosed the full extent of the impact, leaving the number of affected clients and their geographic distribution unclear. However, the firm has taken steps to secure its internal systems and has engaged with federal law enforcement regarding the breach.
- Global revenue reported by the firm reached $53.2 billion.
- The unauthorized access period lasted from March 28 to April 12.
- Affected clients are being offered 24 months of identity monitoring and restoration services.
- Enrollment for the identity protection services must be completed by October 31, 2026.
Remediation and Mitigation Efforts
In response to the incident, the firm has stated it has no current knowledge of any misuse of the stolen files or evidence that individual clients were specifically targeted. To assist those affected, Ernst & Young is providing identity monitoring through Experian. Despite the severity of the unauthorized access, no ransomware groups or threat actors have claimed responsibility for the intrusion at this time.
Industry and Client Implications
This incident illustrates the persistent risk third-party systems present to even the largest professional service firms. For clients, the reliance on notification sample materials provided by the firm is a necessary step to determine if their specific information was part of the impacted cache. Given the 24-month monitoring window, the firm’s response suggests that the long-term risk of identity fraud remains a primary concern, even in the absence of current evidence of malicious data exploitation.
Sources
- BleepingComputer Original source
- notification sample Also reporting
Continue Reading
Faronics Deploy Abused in ScreenConnect Attacks
Hackers exploit Faronics Deploy to enroll victims and install ScreenConnect, researchers report.
Palo Alto Networks Buys Console for Agentic Security
Palo Alto Networks acquires Console, an AI-native agentic workflow platform, to deepen Cortex's autonomous security capabilities.
Meta's $17B Settlement
EFF says Meta's proposed $17 billion settlement fails to protect teens and could harm all users' privacy.