EY breach threatens to expose client tax data
Ernst & Young says an unauthorized party accessed an IT platform and downloaded client documents. ShinyHunters claims responsibility and threatens to publish the data, but EY has not verified that claim.
- Report priority
- High
- Victim
- Ernst & Young
What is known
- An unauthorized party accessed EY's IT service management platform between March 28 and April 12, 2026.
- The party downloaded documents associated with multiple EY clients.
- Exposed support tickets may contain attachments used in tax preparation workflows.
- ShinyHunters says a third-party support compromise provided access, but that claim remains unverified.
What to do
If you are an EY client and receive a breach notification, review it for confirmation that your information was involved.
Affected individuals can use EY's offered two years of credit monitoring and identity restoration services, following the instructions in their notice.
Reported details
EY said the accessed environment contained support tickets. Those tickets may contain attachments used in tax preparation workflows. Potentially exposed information includes names, addresses, Social Security numbers, financial account details, payment card data, and tax-filing records.