• 2 min read
EY says hack exposed client tax data for weeks
Ernst & Young says attackers accessed tax-related support tickets from March 28 to April 12, 2026, through a third-party platform.

Image: TechRadar
Ernst & Young (EY) has disclosed a data breach after attackers gained access to a third-party IT service management platform used by its internal support team, exposing sensitive client information including tax data.
In a notification letter to affected individuals, EY said it detected “anomalous activity” on April 23, 2026 inside the external platform. The system is used by EY staff to support teams handling client tax work, and support tickets can include documents containing tax information.
EY said its investigation found the attackers had access from March 28, 2026, until April 12, 2026, during which they exfiltrated files. The company did not disclose exactly what data was taken, how many clients were affected, or whether the incident was limited to the US or also involved customers in other countries.
The firm said it activated its incident response process, brought in third-party cybersecurity specialists, notified relevant authorities, and contacted affected clients. EY also said the attackers have been removed from its systems and the affected environment has been secured.

Recommended reading
WordPress bugs are now under attack at scale
So far, no hacking group has claimed responsibility, and the stolen data has not appeared on the dark web, according to the report. EY is offering affected customers 24 months of free identity monitoring and restoration services through Experian.
Customers are being urged to watch for unsolicited emails, particularly messages pretending to come from EY.
EY is one of the Big Four professional services networks, headquartered in London and operating across more than 150 countries with more than 400,000 employees. Its business spans assurance, tax, consulting, and M&A strategy.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


