Summary
Key Points:
- Ernst & Young (EY) experienced a data breach involving a compromised third-party IT support ticket system, leading to unauthorized access to client documents and tax information.
- The breach occurred between March 28 and April 12, 2026, with attackers downloading sensitive personal and financial data. EY has since secured its systems and is investigating the incident with external cybersecurity experts.
- It is recommended that affected clients take advantage of EY's offer for 24 months of identity monitoring and restoration services through Experian to mitigate potential risks.
Technical Details: The breach involved unauthorized access to a third-party service management platform used by EY, which may have contained sensitive client tax documents. The specific attack vector has not been disclosed.
MITRE ATT&CK Techniques: None mentioned
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.