Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Hacked! Ernst & Young informs clients of third-party data breach

Big four accounting firm Ernst & Young tells clients that their financial and tax data was accessed by a hacker over a more-than-two-week period in early 2026.

Tue, 21 Jul 2026
Hacked! Ernst & Young informs clients of third-party data breach

Earlier this month, multinational professional services firm Ernst & Young (EY) began notifying clients that some of their data had been compromised by a cyber security breach impacting one of its third-party data platforms used to collect & store data client investment data for tax-related services.

“On April 23, 2026, EY identified anomalous activity within that platform,” EY told its clients in a 13 July letter, sent from its New York office and subsequently filed with the California Attorney General’s Office.

“EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts.”

 
 

Since then, EY said it has been working with an “independent cyber security firm” to continue its investigation and confirm containment. However, it may be too late for the data held on that unnamed third-party platform, which appears to have stored data related to the tax services EY provides for several large financial institutions, as EY explained in the letter.

The individual data compromised is described on a per-client basis in the letter, with placeholder text in the version filed with California’s Attorney General. However, Cyber Daily understands the data includes personal details, Social Security numbers, credit card details, and – according to the letter – “certain financial information contained or used to prepare tax filings”.

While EY did not elaborate further on the number of clients impacted by the incident or the identity of the hacker, the firm did outline the nature of the incident itself.

“Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorised third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients,” EY said.

EY said it is not aware of any further exposure of that data, or its misuse, nor does it believe that any specific entity was targeted in the attack. The company also further outlined its response to the incident.

“Upon discovery, we took steps to secure our systems and launched an investigation with third-party specialists to determine the nature and scope of the event, and additionally notified federal law enforcement of this incident,” EY said.

The company is continuing to monitor for any further exposure; however, no threat actor appears to have claimed responsibility for the incident, nor has any EY data been observed in circulation on any underground hacking forum.

Ernst & Young is one of the big four global accounting firms alongside Deloitte, KPMG, and PwC. The company is headquartered in the UK and has offices globally, including in Australia.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.