Ernst & Young LLP, one of the world’s “Big Four” accounting firms, has begun notifying individuals that their personal and financial information was compromised after an unauthorized party breached a third-party IT service management platform that supports the firm’s tax operations.
EY relies on a third-party information technology service management platform to help its internal IT teams support staff performing tax-related work for clients, and support tickets submitted through this platform often contained documents with sensitive client tax information.
The firm detected anomalous activity within the platform on April 23, 2026, prompting its Information Security team to immediately launch incident response procedures to determine the scope of the intrusion, contain it, and begin remediation.
EY Confirms Data Breach
EY’s subsequent investigation, conducted with an independent cybersecurity firm, determined that an unauthorized third party had actually accessed the platform and exfiltrated documents between March 28, 2026, and April 12, 2026, nearly three weeks before the breach was discovered.
The compromised information tied to affected individuals’ investment holdings includes unspecified personal data elements, as well as financial information contained in, or used to prepare, tax filings.
This is notable because tax documents typically bundle highly sensitive identifiers Social Security numbers, income details, and account information making them a high-value target for identity thieves and tax-fraud schemes.
EY stated it has no current evidence that the stolen data has been misused or further disseminated, nor any indication that specific individuals were deliberately targeted.
EY confirmed that the unauthorized access has been stopped and its systems are now secure, and the firm has notified federal law enforcement of the incident while continuing to monitor for any further exposure of affected data.
Notification letters, dated July 13, 2026, are being sent to affected individuals across multiple U.S. states, with disclosures tailored to state-specific breach notification laws in jurisdictions including Maryland, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C.
Rhode Island’s notice alone references approximately seven residents affected in that state, suggesting the incident’s footprint spans a broad, multi-state population of EY’s institutional clients and their underlying investors.
To mitigate downstream harm, EY is offering affected individuals complimentary 24-month enrollment in Experian’s IdentityWorks credit and identity monitoring service, along with Identity Restoration support that is available regardless of enrollment status.
The package includes credit monitoring across all three major bureaus, up to $1 million in identity theft insurance, and Experian’s ExtendCARE support that continues even after the membership period lapses.
Enrollment must be completed by 11:59 p.m. UTC on October 31, 2026, using individual activation codes provided in each notification letter.
EY also directed recipients toward IRS Identity Protection PINs, credit freezes, and fraud alerts as additional safeguards against tax-related identity theft.
The breach underscores a persistent weak link in enterprise security: third-party IT service management platforms that aggregate sensitive support documentation often sit outside the primary organization’s direct security perimeter, yet pose outsized risk when compromised.
For a firm handling tax data across “a wide range of financial institutions globally,” even a contained, three-week intrusion window can translate into a sprawling, multi-jurisdictional notification obligation.