Ernst & Young (EY), a leading professional services firm, disclosed a data breach affecting its clients' personal and financial information. The breach originated from a third-party support ticket system used for handling tax-related client information.
The unauthorized access spanned from March 28 to April 12. EY discovered the breach on April 23, prompting an investigation with external cybersecurity experts. This helped determine the extent of data accessed by hackers.
The breach involved sensitive client data such as Social Security numbers and bank account details. This information was contained within documents used for preparing tax filings. Specific data types were not disclosed in the initial notifications.
Ernst & Young has begun notifying affected clients and state regulators about the incident. Notifications were sent to the California Attorney General and similar filings were made in other states such as Massachusetts and Vermont.
This incident highlights the risks associated with third-party IT systems, urging companies to reassess their digital security measures. Clients affected by the breach are advised to take precautionary actions to safeguard their personal information.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The ShinyHunters extortion group has claimed responsibility for the recent Ernst & Young (EY) data breach, which compromised client tax-related information from a third-party service management platform. This development identifies the perpetrators behind a significant data exposure affecting a major professional services firm and its clients.
The ShinyHunters extortion gang has claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials through a supply-chain attack and accessed internal systems. This development adds a new dimension to the previously disclosed breach, with a threat to release stolen data if EY does not engage by July 31, 2026.
Ernst & Young reported a data breach affecting client tax information due to a third-party IT support system vulnerability. From March 28 to April 12, attackers accessed sensitive customer details, prompting EY to inform affected clients and state regulators.
Ernst & Young has notified clients of a data breach affecting their personal and financial data, discovered on April 23. Hackers accessed a third-party service management platform between March 28 and April 12, compromising client information such as Social Security numbers and bank account details.
Ernst & Young disclosed a data breach stemming from a third-party support ticket system hack. Compromised client tax information may have been accessed, impacting privacy and security for affected customers.