EY Breach: What Was Taken, Who's Affected, and What Clients Should Do
Analysis of the Ernst & Young (EY) breach exposing confidential audit workpapers, M&A filings, and client dossiers.
What Happened
Ernst & Young confirmed that an unauthorized third party accessed a third-party IT service management platform used by EY support staff, between late March and mid-April 2026, and downloaded documents related to a number of EY clients. EY identified anomalous activity within the platform in late April and began incident response at that point, meaning there was a gap of several weeks between initial access and detection.
What Was Exposed
The compromised documents reportedly include client tax records along with names, addresses, Social Security numbers, and credit or debit card numbers. Because the access point was a support ticketing platform rather than EY's core systems, the exposure is likely uneven across clients, some may have had sensitive attachments sitting in old support tickets, others may not be affected at all, which is part of why EY has not yet said misuse has been confirmed.
Why This Matters Beyond EY
EY is one of the largest professional services firms globally, and a breach touching client tax data creates knock-on risk well outside EY's own walls: exposed Social Security numbers and financial details can be used for tax fraud, identity theft, and highly targeted phishing that references real account or case details pulled from support tickets.
Risk Areas to Assess
Tax data exposure: Social Security numbers and payment card numbers in the exposed documents create a direct identity-theft and tax-fraud risk for named individuals.
Detection gap: the multi-week delay between compromise and detection means attackers had time to access and potentially exfiltrate data undetected, so assume any exposure window is wider than the confirmed access dates.
Third-party platform risk: this breach originated in a third-party support tool, not EY's primary infrastructure, underscoring that vendor and support-tooling access is a real attack surface even for firms with mature security programs.
Remediation
If you are an EY client, or a client of an EY client whose data may have moved through EY, ask your EY account team whether your data appears in the disclosed documents and request specifics rather than a general assurance. Individuals whose Social Security numbers may be exposed should consider placing a credit freeze and enrolling in identity-theft monitoring, and should be alert to unexpected tax filings or IRS notices this filing season. Watch for phishing that references real support-ticket details, since attackers commonly use authentic-looking internal information to make follow-on social engineering more convincing.
Related
This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.