← All stories
● Covered by 3 sources · 5 reportsMedium impact2 negative

Ernst & Young Discloses Data Breach: Client Tax Information Compromised

🔄 Updated 72d ago — new reporting from BleepingComputer, SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Breach stemmed from a third-party support system vulnerability.
  • Data compromised includes personal and financial client tax details.
  • The breach occurred between March 28 and April 12.
  • Ernst & Young is notifying affected clients and regulators.
  • Company engaged external cybersecurity experts post-breach.

Data Breach Overview

Ernst & Young (EY), a leading professional services firm, disclosed a data breach affecting its clients' personal and financial information. The breach originated from a third-party support ticket system used for handling tax-related client information.

Breach Timeline and Investigation

The unauthorized access spanned from March 28 to April 12. EY discovered the breach on April 23, prompting an investigation with external cybersecurity experts. This helped determine the extent of data accessed by hackers.

Compromised Information

The breach involved sensitive client data such as Social Security numbers and bank account details. This information was contained within documents used for preparing tax filings. Specific data types were not disclosed in the initial notifications.

Response and Notifications

Ernst & Young has begun notifying affected clients and state regulators about the incident. Notifications were sent to the California Attorney General and similar filings were made in other states such as Massachusetts and Vermont.

Implications for Clients

This incident highlights the risks associated with third-party IT systems, urging companies to reassess their digital security measures. Clients affected by the breach are advised to take precautionary actions to safeguard their personal information.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub uuidjs/uuid

How outlets covered it

The ShinyHunters extortion group has claimed responsibility for the recent Ernst & Young (EY) data breach, which compromised client tax-related information from a third-party service management platform. This development identifies the perpetrators behind a significant data exposure affecting a major professional services firm and its clients.

The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials through a supply-chain attack and accessed internal systems. This development adds a new dimension to the previously disclosed breach, with a threat to release stolen data if EY does not engage by July 31, 2026.

Ernst & Young reported a data breach affecting client tax information due to a third-party IT support system vulnerability. From March 28 to April 12, attackers accessed sensitive customer details, prompting EY to inform affected clients and state regulators.

Ernst & Young has notified clients of a data breach affecting their personal and financial data, discovered on April 23. Hackers accessed a third-party service management platform between March 28 and April 12, compromising client information such as Social Security numbers and bank account details.

Ernst & Young disclosed a data breach stemming from a third-party support ticket system hack. Compromised client tax information may have been accessed, impacting privacy and security for affected customers.