EY Breach Exposes Sensitive Tax Data
A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.
Professional services firm Ernst & Young has begun notifying clients of a data security incident that compromised personal and financial records. The breach originated within a third-party service management platform utilized by the firm to facilitate tax-related workflows.
Unauthorized Platform Access Identified
The security incident was discovered on April 23, prompting the firm to initiate incident response procedures, including remediation and recovery efforts. According to filed documentation, the company also engaged an independent cybersecurity firm to conduct a forensic investigation into the scope and nature of the intrusion.
Scope of Data Exposure
Internal investigations indicate that unauthorized parties maintained access to the platform for a period of several weeks. The stolen documents contain information critical to tax preparation, including:
- Names and residential addresses
- Social Security numbers
- Financial account identifiers
- Credit and debit card numbers
Timeline of the Intrusion
The firm has established a specific window during which the unauthorized activity occurred on the compromised infrastructure. The details regarding the duration of the exposure are as follows:
- Incident discovery date: April 23
- Unauthorized access window: March 28 to April 12
- Remediation provided: 2 years of credit and identity monitoring
Support tickets submitted through the platform may include documents containing client tax information.
— Ernst & Young, in a notification letter sent to clients
Implications for Data Custodians
While the firm reports that it is not currently aware of any active misuse of the compromised information, the nature of the exposed data—specifically Social Security and financial account numbers—presents a long-term risk for affected individuals. This incident serves as a reminder of the heightened threat profile associated with third-party service providers who aggregate sensitive client documentation. For organizations, the event underscores the importance of rigorous security oversight and continuous auditing of the platforms used by partners, as the failure of a single external tool can create significant downstream consequences for client privacy and regulatory compliance.
Continue Reading
Estée Lauder Breach Tied to Oracle Flaw
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
LLM-Assisted Phishing Kits Scale Attacks
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
Cruciferra Crypter Evolves Malware Tactics
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
Sources
- SecurityWeek Original source
- filed Also reporting