Ernst & Young is notifying clients of a data breach after attackers compromised a third-party support ticket system used by the firm’s IT personnel and downloaded documents belonging to an unknown number of EY clients. The Big Four accounting and consulting giant filed breach notifications with the California Attorney General on July 15, 2026, and with regulators in Vermont and other states in the days that followed.

It is the second breach EY has had to disclose in under a year — and this one cuts closer to the bone, exposing the personal and financial data behind clients’ tax filings rather than the internal credentials spilled by its earlier cloud blunder.

What happened

EY detected anomalous activity on the third-party platform on April 23, 2026. Working with an independent cybersecurity firm, investigators determined that an unauthorized party had access to the system between March 28 and April 12, 2026, and during that window downloaded documents pertaining to a number of EY clients.

The compromised platform was not EY’s own core network but a vendor-operated support ticket system its IT staff relied on — the kind of back-office tooling that accumulates sensitive attachments precisely because it exists to help resolve problems involving that data. EY has not publicly named the vendor, and no ransomware or data-extortion group has claimed responsibility.

The data that walked out

According to EY’s filings, the exposed documents contained personal information tied to individuals’ investment holdings with EY’s institutional clients, alongside financial information used in preparing tax filings.

A separate notification to the Vermont Attorney General went further, indicating the exposure may have included:

  • Social Security numbers
  • Financial account numbers and account access codes
  • Credit or debit card information
  • Names, addresses, dates of birth, driver’s license numbers, emails and phone numbers

That combination — identity, financial account, and tax data in one place — is close to a complete kit for identity theft and tax-refund fraud. EY has not disclosed how many people were affected, and the number remains unclear.

EY’s response

EY notified federal law enforcement and is offering affected individuals 24 months of identity monitoring and restoration through Experian IdentityWorks. Letter recipients are urged to enroll by 11:59 p.m. UTC on October 31, 2026.

The firm has not attributed the intrusion to any threat actor, nor explained how the third party’s platform was accessed. That silence — no named vendor, no named attacker, no victim count — is already drawing scrutiny, and plaintiff’s firms including Edelson Lechtzin and others have announced investigations into potential class-action claims on behalf of affected clients.

Two breaches, one lesson

This is not EY’s first bad headline of the cycle. In October 2025 the firm exposed a 4TB SQL Server backup on Microsoft Azure — an unencrypted database stuffed with API keys, session tokens, and service-account passwords that a Dutch security firm stumbled onto during routine reconnaissance. That was a self-inflicted cloud misconfiguration. This one is a third-party compromise.

The two incidents rhyme in the way that matters: a firm whose entire business is advising others on risk keeps getting burned on the boring, unglamorous parts of its own security posture — a misconfigured storage bucket in one case, an under-scrutinized vendor platform in the next. For a company that audits controls for a living, the pattern is uncomfortable.

The supply-chain angle here is the one worth internalizing. EY’s core defenses may well have held; the breach happened in a system it did not fully control but did feed with sensitive client data. That is the same structural weakness behind a long run of 2026’s worst incidents — attackers no longer need to breach the fortress when they can walk in through a supplier’s side door. Every ticket system, every support portal, every managed platform that touches regulated data is an extension of the attack surface, whether or not it shows up on the org chart.

What affected clients should do

  • Enroll in the offered Experian monitoring before the October 31 deadline.
  • File an IRS Identity Protection PIN if tax data may be involved — it blocks fraudulent returns filed in your name.
  • Freeze credit with the three major bureaus; it is free and reversible.
  • Watch financial accounts named in any breach letter for unauthorized access, given that account numbers and access codes may be exposed.

Sources