EY Breach Exposes Sensitive Tax Data
A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.
Professional services firm Ernst & Young has begun notifying clients of a data security incident that compromised personal and financial records. The breach originated within a third-party service management platform utilized by the firm to facilitate tax-related workflows.
Unauthorized Platform Access Identified
The security incident was discovered on April 23, prompting the firm to initiate incident response procedures, including remediation and recovery efforts. According to filed documentation, the company also engaged an independent cybersecurity firm to conduct a forensic investigation into the scope and nature of the intrusion.
Scope of Data Exposure
Internal investigations indicate that unauthorized parties maintained access to the platform for a period of several weeks. The stolen documents contain information critical to tax preparation, including:
- Names and residential addresses
- Social Security numbers
- Financial account identifiers
- Credit and debit card numbers
Timeline of the Intrusion
The firm has established a specific window during which the unauthorized activity occurred on the compromised infrastructure. The details regarding the duration of the exposure are as follows:
- Incident discovery date: April 23
- Unauthorized access window: March 28 to April 12
- Remediation provided: 2 years of credit and identity monitoring
Support tickets submitted through the platform may include documents containing client tax information.
— Ernst & Young, in a notification letter sent to clients
Implications for Data Custodians
While the firm reports that it is not currently aware of any active misuse of the compromised information, the nature of the exposed data—specifically Social Security and financial account numbers—presents a long-term risk for affected individuals. This incident serves as a reminder of the heightened threat profile associated with third-party service providers who aggregate sensitive client documentation. For organizations, the event underscores the importance of rigorous security oversight and continuous auditing of the platforms used by partners, as the failure of a single external tool can create significant downstream consequences for client privacy and regulatory compliance.
Sources
- SecurityWeek Original source
- filed Also reporting
Continue Reading
Unicode Trick Fuels Million-Email Phishing Surge
A campaign hides 'funding' lure words with invisible Unicode tags, splitting keywords to slip past filters.
French hospital fined €500,000 after breach exposes data of 727,000
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.
AI-Driven Malware Marks Exilwire's Underground Trade in Breached Hosts
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.