Advertisement
Cyber CrimeDeveloping Story

EY Breach Exposes Sensitive Tax Data

A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.

··15 hours ago·1 min read
brown padlock on black computer keyboard
Photo by FlyD on Unsplash
Advertisement

Professional services firm Ernst & Young has begun notifying clients of a data security incident that compromised personal and financial records. The breach originated within a third-party service management platform utilized by the firm to facilitate tax-related workflows.

Unauthorized Platform Access Identified

The security incident was discovered on April 23, prompting the firm to initiate incident response procedures, including remediation and recovery efforts. According to filed documentation, the company also engaged an independent cybersecurity firm to conduct a forensic investigation into the scope and nature of the intrusion.

Scope of Data Exposure

Internal investigations indicate that unauthorized parties maintained access to the platform for a period of several weeks. The stolen documents contain information critical to tax preparation, including:

  • Names and residential addresses
  • Social Security numbers
  • Financial account identifiers
  • Credit and debit card numbers

Timeline of the Intrusion

The firm has established a specific window during which the unauthorized activity occurred on the compromised infrastructure. The details regarding the duration of the exposure are as follows:

  • Incident discovery date: April 23
  • Unauthorized access window: March 28 to April 12
  • Remediation provided: 2 years of credit and identity monitoring

Support tickets submitted through the platform may include documents containing client tax information.

— Ernst & Young, in a notification letter sent to clients

Implications for Data Custodians

While the firm reports that it is not currently aware of any active misuse of the compromised information, the nature of the exposed data—specifically Social Security and financial account numbers—presents a long-term risk for affected individuals. This incident serves as a reminder of the heightened threat profile associated with third-party service providers who aggregate sensitive client documentation. For organizations, the event underscores the importance of rigorous security oversight and continuous auditing of the platforms used by partners, as the failure of a single external tool can create significant downstream consequences for client privacy and regulatory compliance.

#data breach#ernst & young#cybersecurity#tax fraud#third-party risk

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement