The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers.
EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026.
A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026.
As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns.
EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information.
The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies.
Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian.
The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026.
At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web.
The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same.
Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.
Read the original article: