July 2026: Big Four firm Ernst & Young LLP is notifying clients that an unauthorized party broke into a third-party IT support / service-management platform used by EY IT staff—and downloaded documents tied to tax work. Access ran from March 28 to April 12, 2026. EY spotted odd activity on April 23. It has not published how many people were hit.
The story matters because support tickets are where sensitive attachments go to die quietly: tax packs, investment schedules, client PII sitting in a vendor tool that IT uses every day. One compromised platform can touch many institutional clients at once.
What happened
Per EY's sample notice and reporting by BleepingComputer, EY uses a third-party ITSM platform so its IT personnel can support teams doing tax work for financial-institution clients. Tickets can include documents with client tax information.
On April 23, 2026, EY saw anomalous activity on that platform and started incident response with an independent cybersecurity firm. Forensics concluded an unauthorized third party had already accessed the system between March 28 and April 12 and downloaded documents for a number of EY clients.
EY says it secured the environment, notified federal law enforcement, and is not aware of misuse or evidence that particular individuals were targeted. California AG sample notice materials (letter dated July 13, 2026; reporting window around mid-July) accompany the disclosure.
What data was exposed
The notice states affected personal information includes certain data elements (placeholders in the sample letter) plus financial information contained in or used to prepare tax filings, in the context of investment holdings EY processed for institutional clients.
EY has not listed a public headcount of affected individuals. Treat any exact figure circulating online without a company or regulator citation as unverified.
What this is not
This is separate from the ~4TB Azure SQL Server backup exposure tied to EY's Italian entity that researchers flagged publicly accessible in late 2025. It is also distinct from EY's earlier MOVEit-related notifications. Same brand, different failure modes.
Who is at risk
People who receive an EY notice letter—typically end customers of financial institutions that used EY for tax services—should assume tax-related identity and financial details may have been in the stolen files. Institutional clients whose tax work flowed through that support queue are also in scope.
What you should do
- If you received an EY letter, enroll in the offered 24-month Experian IdentityWorks monitoring by October 31, 2026 using the activation code in your letter.
- Watch for tax-season phishing: fake IRS/HMRC notices, "EY document portal" links, or urgent requests to re-send W-2/1099-style forms.
- Review investment and bank statements for unexpected account openings or tax-refund redirects.
- Consider a credit freeze / fraud alert if your letter lists SSN or similarly high-risk identifiers.
- Canonical record: Ernst & Young LLP support-platform breach on BreachHistory.
Sources: BleepingComputer; EY sample notice (California AG file); Cyber Security News.