Key takeaway: EY customers exposed their tax documents between March and April 2026 through a compromised support ticketing access point, with the exact number of affected customers remaining unclear.
Accounting firm Ernst & Young (EY) has informed customers of a security incident: Unknown attackers gained access to an IT service management platform operated by an external service provider between March 28 and April 12, 2026, and downloaded multiple documents containing customer tax information.
The IT service management platform is used by EY to support IT personnel who assist teams with tax-related work for customers. Support tickets may contain documents with tax information. On April 23, 2026, EY discovered anomalous activity within the platform. The unauthorized access occurred between March 28 and April 12, 2026.
The compromised data includes personal and financial information used in or contained within tax return filings. EY has not disclosed the exact number of affected customers or clarified whether the incident occurred only in the United States or also affects other countries. The categories of compromised data vary depending on the recipient.
Following discovery of the incident on April 23, EY’s internal information security team initiated an investigation and engaged an independent cybersecurity firm. Unauthorized access was terminated and systems were secured. U.S. federal law enforcement authorities were informed. According to EY, there is currently no evidence of misuse or further distribution of the data, and no ransomware or extortion group has claimed responsibility for the attack.
EY is offering affected customers 24 months of complimentary identity monitoring through Experian. Registration must be completed by October 31, 2026. EY employs approximately 406,000 people worldwide and generated global revenue of $53.2 billion in the last fiscal year.
Source: www.it-daily.net · Published July 20, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.