Powered by MOMENTUMMEDIA

EY tells clients of third-party data breach

Profession
22 July 2026
ernst young tells clients of third party data breach

EY US has informed clients that a hacker accessed their financial and tax data over a more than two-week period in early 2026.

Editor’s note: This story first appeared on Accounting Times’ sister brand, Cyber Daily.

Earlier this month, multinational professional services firm Ernst & Young began notifying clients that some of their data had been compromised by a cyber security breach impacting one of its third-party data platforms.

“On April 23, 2026, Ey identified anomalous activity within that platform,” EY told its clients in a 13 July letter, which was subsequently filed with the California Attorney General’s Office.

 
 

“EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts.”

Since then, EY said it has been working with an “independent cyber security firm” to continue its investigation and confirm containment. However, it may be too late for the data held on that unnamed third-party platform, which appears to have held data related to the tax services EY provides for several large financial institutions, as EY said in the letter.

The individual data compromised is described on a per-client basis in the letter, with placeholder text in the version filed with California’s Attorney General. Cyber Daily understands the data includes personal details, Social Security numbers, credit card details, and – according to the letter – “certain financial information contained or used to prepare tax filings”.

While EY did not elaborate further on the number of clients impacted by the incident, or the identity of the hacker, the firm did outline the nature of the incident itself.

“Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorised third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients,” EY said.

EY said it is not aware of any further exposure of that data, or its misuse, nor does it believe that any specific entity was targeted in the attack. The company also further outlined its response to the incident.

“Upon discovery, we took steps to secure our systems and launched an investigation with third-party specialists to determine the nature and scope of the event, and additionally notified federal law enforcement of this incident,” EY said.

The company is continuing to monitor for any further exposure; however, no threat actor appears to have claimed responsibility for the incident, nor has any EY data been observed in circulation on any underground hacking forum.

Want to see more stories from trusted news sources?
Make Accounting Times a preferred news source on Google.
Click here to add Accounting Times as a preferred news source.