EY breach threatens to expose client tax data

Published July 27, 2026

Ernst & Young says an unauthorized party accessed an IT platform and downloaded client documents. ShinyHunters claims responsibility and threatens to publish the data, but EY has not verified that claim.

Report priority
High
Victim
Ernst & Young

What is known

  • An unauthorized party accessed EY's IT service management platform between March 28 and April 12, 2026.
  • The party downloaded documents associated with multiple EY clients.
  • Exposed support tickets may contain attachments used in tax preparation workflows.
  • ShinyHunters says a third-party support compromise provided access, but that claim remains unverified.

What to do

If you are an EY client and receive a breach notification, review it for confirmation that your information was involved.

Affected individuals can use EY's offered two years of credit monitoring and identity restoration services, following the instructions in their notice.

Reported details

EY said the accessed environment contained support tickets. Those tickets may contain attachments used in tax preparation workflows. Potentially exposed information includes names, addresses, Social Security numbers, financial account details, payment card data, and tax-filing records.