Jul 21, 2026 · 6 min read
EY Breach Exposed Client Tax Data, Disclosed 3 Months Later
Hackers accessed a third party IT support platform used by EY's tax teams between late March and mid April 2026, downloading documents packed with client Social Security numbers and financial records. EY did not notify regulators until July 15.
EY, one of the world's four largest accounting and consulting firms, has disclosed a data breach that exposed personal and financial information belonging to clients of its tax practice. According to breach notifications filed with the California and Texas Attorneys General on July 15, 2026, an unauthorized third party accessed a support ticket platform used by EY's IT help desk staff between March 28 and April 12, 2026, and downloaded documents attached to those tickets. EY says it detected the anomalous activity on April 23, more than three weeks after the access began, and only made the incident public nearly three months after that.
The breach is a reminder of a pattern that keeps repeating across corporate America: the weakest point in a company's security is often not its own network, but a smaller third party vendor plugged into it. In this case, that vendor was the help desk software EY's own staff used to log routine IT problems, which turned out to double as an unintentional filing cabinet for some of the most sensitive documents a tax firm handles.
Key Takeaways
- Hackers accessed EY's third party IT support ticketing platform between March 28 and April 12, 2026, and downloaded documents containing client tax data.
- EY detected the intrusion on April 23, 2026, but did not file breach notifications with regulators until July 15, 2026, nearly three months later.
- Stolen documents included names, addresses, Social Security numbers, account numbers, card numbers, and tax preparation files tied to EY's institutional clients.
- EY has not named an attacker, disclosed how many clients were affected, or confirmed whether states beyond California and Texas were notified.
- EY is offering two years of complimentary credit monitoring, identity monitoring, and identity restoration services to affected individuals.
How Did Hackers Get Into EY's Systems?
The attackers did not breach EY's core network directly. Instead, according to SecurityWeek's reporting, they compromised a third party service management platform that EY's IT help desk uses to track and resolve internal support tickets. EY's own notice explains the exposure in plain terms: "Support tickets submitted through the platform may include documents containing client tax information," because staff routinely attached files to tickets when troubleshooting client account issues. That made a routine IT tool into an accidental archive of exactly the kind of documents a tax firm is supposed to protect most carefully.
No ransomware gang or extortion group has claimed responsibility, and EY has not disclosed how the attacker first got into the platform, whether through stolen credentials, an unpatched vulnerability, or a misconfiguration. EY says it engaged an independent cybersecurity firm to investigate and that it found "no current evidence of misuse of the exposed data or indication that specific individuals were deliberately targeted," but that assurance covers only what has been observed so far, not what is possible with data that is already out of EY's control.
What Data Did the Attackers Steal?
The exposed documents reportedly included names, home addresses, Social Security numbers, bank account numbers, credit and debit card numbers, and tax preparation files, along with information tied to individuals' investment holdings with EY's institutional clients. That is close to a complete identity theft kit for anyone affected: the combination of a Social Security number, a home address, and financial account details is enough to open new lines of credit, file fraudulent tax returns, or pass identity checks at a bank. EY has not disclosed a specific count of affected individuals or named the platform vendor involved, which makes it difficult for outside researchers or affected clients to independently gauge the scale of the exposure.
Why Did EY Wait Nearly 3 Months to Disclose It?
EY detected the anomalous activity on April 23, 2026, but did not file breach notifications until July 15, a gap of roughly 83 days. Most state breach notification laws, including California's, require disclosure "without unreasonable delay," but they also carve out time for a company to investigate the scope of a breach and coordinate with law enforcement before going public, which is the explanation companies typically give for gaps like this one. EY has not detailed what happened during those three months, and the firm is already facing scrutiny over the delay: law firms including Edelson Lechtzin have opened investigations into potential class action claims on behalf of affected clients, arguing the notification came too slowly for people to protect themselves in the meantime.
What Should EY Clients Do Now?
EY is offering two years of complimentary credit monitoring, identity monitoring, and identity restoration services to individuals it has identified as affected, but clients should not wait for a notification letter to act if they have worked with EY's tax practice recently. A few concrete steps matter more than watching for a letter:
- Place a credit freeze with all three major bureaus, which blocks new accounts from being opened in your name even if your Social Security number has been exposed.
- File your tax return as early as possible next season, since a stolen Social Security number is commonly used to file a fraudulent return and claim someone else's refund first.
- Watch bank and card statements closely for small test transactions, which attackers often use to verify that stolen card numbers still work before larger fraud.
- Enroll in the credit monitoring EY is offering, but treat it as a backstop rather than a substitute for a credit freeze, since monitoring only alerts you after new activity occurs.
- Be skeptical of any follow up email claiming to be from EY about the breach, since large disclosures like this one are reliably followed by phishing campaigns that impersonate the breached company.
The underlying lesson extends well past EY. LastPass confirmed customer data stolen through a compromised vendor just weeks earlier, and Nextcloud's leak exposed hundreds of thousands of client files and emails through a similar third party gap. In each case, the exposure traced back to a support tool or vendor system that sat one step removed from the primary network, and one step removed from the security scrutiny that primary network gets.
EY says it has closed off the specific access point the attacker used, but the firm still has not answered the questions that matter most to affected clients: how many people were exposed, how the attacker got in, and why it took nearly three months to tell anyone. Until EY provides a fuller accounting, the safest assumption for anyone who has submitted a support ticket to EY's tax practice this year is that their information may already be circulating.
Sources: SecurityWeek, Cyber Security News, and UpGuard.