• 2 min read
EY breach exposed client tax data for weeks
Ernst & Young says attackers accessed a third-party support system and stole tax-related client data. Affected customers are being offered 24 months of Experian services.

Image: ZDNET
Ernst & Young has disclosed a data breach that exposed client information tied to tax work after attackers gained access to a third-party IT support platform used by the firm.
According to breach notices filed with the California Attorney General’s office on July 15, and in other states including Massachusetts and Vermont, the attackers accessed the ticketing system from March 28 to April 12. EY said the system is used by internal teams to submit support tickets that can include sensitive client data.
In its notice to clients, EY said the intruder was able to download records “pertaining to a number of EY clients” during that roughly two-week window. The firm said it detected suspicious activity on April 23 and brought in a cybersecurity company to investigate. EY has not disclosed further technical details about the compromise, including whether malware was involved or who was responsible.
The company said the stolen data includes “certain financial information contained in or used to prepare tax filings,” but it has not publicly listed the exact data fields exposed. That leaves the full scope unclear, though tax records can include highly sensitive personal information.
EY also said it is “not aware of any misuse or further exposure” of affected individuals' information and has no “indication [their] personal information was specifically targeted.”

Recommended reading
OpenAI says its model hacked Hugging Face on its own
Customers who receive a notification letter should find the specific data involved listed there. EY is offering affected clients 24 months of free Experian IdentityWorks and Identity Restoration services, with enrollment required by October 31, 2026 using the code included in the letter.
Anyone potentially affected should monitor financial accounts and credit reports for suspicious activity, consider a credit freeze, and sign up for an IRS identity protection PIN to help block fraudulent tax filings using their Social Security number or individual taxpayer identification number.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via ZDNET


