
Follow ZDNET: Add us as a preferred source on Google.
ZDNET’s key takeaways
- Ernst & Young suffered a data breach traced to a third-party IT support system.
- Cybercriminals stole tax-related information from clients.
- Here’s what to do right away if your data was affected.
Ernst & Young has disclosed a data breach that resulted in the theft of clients’ personal information. From March 28 to April 12, attackers had access to a third-party support ticket system containing customer information related to their tax affairs.
Also: Is that QR code a trap? How to spot quishing scams before it’s too late
A ticket support system becomes the target
A data breach notice was filed with the California Attorney General’s office on July 15, as well as other states, including Massachusetts and Vermont. Ernst & Young has since begun notifying customers of the security incident.
According to the organization’s notice to clients [PDF], the data breach was caused by an intrusion into a third-party IT platform that Ernst & Young uses to handle tax-related work for clients. The support system allows Ernst & Young teams to submit support tickets, which may contain sensitive customer information.
Also: I connected ChatGPT to my bank, and it’s my go-to finance app now – here’s how (and why)
For roughly two weeks in March and April, the cybercriminal responsible for the breach was able to download records “pertaining to a number of EY clients,” according to the notice.
Ernst & Young detected suspicious activity on the platform on April 23 and hired a cybersecurity firm to investigate the incident. The support ticket system has now been secured, although no further details — on the compromise, any use of malware, or the responsible party — have been disclosed.
What personal customer data is at risk?
Ernst & Young says in the notification letter that “certain financial information contained in or used to prepare tax filings” and the sample notice includes a placeholder for customers’ specific data points.
The Big Four accounting firm has not disclosed exactly what records were leaked. It is possible that personal, sensitive data necessary for tax filing could be included, such as names, addresses, Social Security numbers, financial account information, and other records, but until Ernst & Young formally discloses this information, we can’t be sure.
Also: The 10-step phone security tune-up you should run every year – and why
EY added in the notice that the organization is “not aware of any misuse or further exposure of [your] personal information as a result of this incident,” and also says there is no “indication [your] personal information was specifically targeted.”
How do I know if I’m impacted?
If you have received a letter from Ernst & Young notifying you of the data breach, it should list the sensitive and financial information that has been stolen.
As we do not know how many clients have been affected, it’s also not possible to say whether every victim has received their letter yet. If you haven’t seen one, this doesn’t mean that you’re in the clear.
Ernst & Young is offering 24 months of two free Experian services for affected customers: IdentityWorks and Identity Restoration, which, combined, can be used for credit monitoring and restoration. You will need to visit Experian’s website and use the code contained in your letter to activate these services before October 31, 2026.
Also: LastPass hit by new data breach – 4 steps you should take now
You should also keep a close eye on your accounts and credit report for any suspicious activity or fraudulent transactions, and you may want to consider freezing your credit for now until more is known about the scale of the incident.
As this data breach involves the theft of tax-related financial information, another measure you should consider to protect yourself is to sign up for an IRS identity protection PIN. This will prevent anyone from filing a tax return on your behalf using your Social Security number or individual taxpayer identification number.


