Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.

According to the company, support tickets submitted through the platform may have included documents containing client tax information.

Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries.

The company employs 406,000 people and reported a global revenue of $53.2 billion last year.

The breach notification to affected clients states that Ernst & Young detected anomalous activity on its networks on April 23 and initiated an investigation.

With help from external cybersecurity experts, the company determined that an unauthorized third party had accessed the said platform between March 28 and April 12 and downloaded multiple documents.

The affected information included certain personal and financial data contained in or used to prepare tax filings. Since the notification sample features a placeholder for the specific data types, the type of the information exposed remains unclear.

Also, the company has not shared exactly how many customers were affected or whether the incident impacts only its U.S. customer base or other countries as well.

Ernst & Young says it secured its systems and notified federal law enforcement authorities, while it has assured that the unauthorized access has been removed.

The company also states that it is not aware of any misuse or further exposure of the stolen files and has no indication that particular individuals were targeted by the threat actors.

To mitigate the risks arising from this exposure, EY offers affected clients 24 months of identity monitoring and restoration service through Experian and urges letter recipients to enroll by October 31, 2026.

At the time of writing, no data extortion or ransomware groups have taken responsibility for the attack on Ernst & Young.

BleepingComputer has contacted EY to learn more about the incident, but we have not yet received a response at the time of publication.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Healthtech firm Xolis suffers data breach impacting 1.4 million people

SoFi confirms third-party data breach at Hong Kong subsidiary

Medtronic notifies customers impacted by ShinyHunters data breach

LastPass confirms data breach in Klue supply chain attack

Texas govt data breach exposes over 3 million driver’s licenses

So these jokers not disclosing what ticketing system got them hacked? that sounds like they want others to be affected.

Is this related to their “cloud migration error”? Since they did specifically say unauthorized party accessed the platform, not breached, hacked, or a variety of other words.https://www.sdxcentral.com/news/ey-subject-of-whopping-4tb-data-breach-following-cloud-migration-error/ Some other fun bits… “On April 23, 2026, EY identified anomalous activity within that platform.” but the attacker was active “between March 28 and April 12.” Better late than waiting for a ransom notice, i guess. Maybe they were running Atlassian and don’t want to finger the vendor because we will all immediately know that they were not up to date.

My two cents would be that it was their internal ticket system from ServiceNow (They are a partner and customer).After reading the notification sample it gives you a few hints. Third party service management solution, internal it supporting staff. Probably got in through breached AD.

New Windows LegacyHive zero-day gives hackers admin privileges

CISA urges immediate action on actively exploited Fortinet flaws

Windows Server 2022 reach end of mainstream support in 90 days

AI broke vulnerability management. Get the guide CISOs use to shift budget to BAS.

Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.

See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.

Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!

Pentest your web apps on-demand. Find what humans miss. Scope and launch a pentest in minutes.

AI is a data-breach time bomb: Read the new report

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.