NEWS
EY’s Data Breach Is Its Third Security Lapse in Three Years
EY told California regulators hackers spent three weeks inside a support ticket system stealing tax data, the firm’s third breach disclosure since 2023.
Ernst & Young has told California regulators that hackers spent roughly three weeks inside a support ticket system used by its own IT staff, downloading tax and investment documents belonging to its clients before anyone noticed. The breach notification, filed with the California Attorney General’s office on July 15, 2026, marks the accounting giant’s third publicly disclosed security lapse since 2023.
EY sells cybersecurity advisory work to some of the same institutions now receiving its breach letters. That contrast sits at the center of this disclosure, because the firm’s own privacy practice promises to fight and prepare against complex cyber-attacks for its clients.
Three Weeks Inside EY’s Support Ticket System
EY spotted anomalous activity on April 23, 2026, and triggered its incident response process immediately. Working with an outside cybersecurity firm, investigators later determined the actual intrusion had started weeks earlier.
An unauthorized third party accessed the platform between March 28 and April 12, 2026, and downloaded documents tied to a number of EY clients during that window. That gap between first access and discovery, about three weeks, gave the intruder time to pull files before EY’s systems flagged anything unusual.
The platform itself was mundane by design. EY uses a third-party IT service management system so its technology staff can support internal teams working on tax-related client engagements, and support tickets filed through it routinely carried attachments containing sensitive client tax information. It is a common workflow shortcut across enterprise IT support desks, and one that turned this ticketing tool into a single point of failure.

What EY Says Was Taken and Who Gets Free Monitoring
The compromised documents contained personal information tied to individuals’ investment holdings with EY’s institutional clients, along with financial information used to prepare tax filings. EY’s letter says it has no current evidence the data has been misused or that specific individuals were targeted.
Ernst & Young, one of the world’s largest professional services firms, employs 406,000 people and reported $53.2 billion in global revenue last year, according to BleepingComputer’s review of the disclosure. The firm has not said exactly how many clients were affected or whether the exposure reaches beyond its U.S. customer base.
EY’s notification outlines what the firm did after discovery:
- Engaged an independent cybersecurity firm to investigate the intrusion
- Secured the affected systems and removed the unauthorized access
- Notified federal law enforcement authorities
- Offered affected clients 24 months of free identity monitoring and restoration service through Experian, with enrollment open through October 31, 2026
The fallout reaches past EY’s direct clients, too. A separate breach notice filed with Massachusetts regulators in June 2026 came from Easterly Government Properties, a real estate investment trust, which told affected individuals that a security incident had occurred at EY, its tax services vendor. Exposed data in that case reportedly included Social Security numbers and taxable income figures. It is a reminder that when a firm processes tax data for institutions worldwide, a single compromised support system can cascade into notifications sent by companies that never touched the breached platform themselves.
What we know
- Detection date: EY flagged anomalous activity on April 23, 2026, and later determined the intrusion window ran from March 28 to April 12, 2026.
- Data exposed: Personal information tied to investment holdings and information used in preparing tax filings.
- Response offered: 24 months of Experian identity monitoring, enrollment deadline October 31, 2026.
What’s unconfirmed
- Total affected: EY has not published a count of impacted individuals or said whether non-U.S. clients are involved.
- Platform vendor: The firm has not named the third-party IT service management platform that was breached.
- Data misuse: EY says there is no current evidence of misuse, but the investigation is ongoing.
After the notice, EY has not offered new detail beyond the letter itself, and outlets including BleepingComputer say the company has not responded to requests for further comment.
EY’s Third Data Exposure Since 2023
This is not an isolated event in EY’s recent history. It is the third time in three years that the firm has disclosed client or internal data landing somewhere it should not have, and each incident traces to a different piece of third-party or cloud infrastructure.
| Incident | Disclosed | Root Cause | Data Exposed |
|---|---|---|---|
| MOVEit Transfer hack | August 2023 | Zero-day SQL injection in third-party file-transfer software | Names, financial account data and card numbers for over 30,210 Bank of America customers |
| Azure SQL backup exposure | October 2025 | Cloud migration error left a 4TB backup file public | API keys, credentials and tokens tied to an acquired EY Italy entity |
| IT support platform breach | July 2026 | Unauthorized access to a third-party ITSM ticketing tool | Investment holdings data and tax filing information |
The 2023 incident came from the mass-exploited MOVEit Transfer flaw that hit Bank of America clients, part of a supply chain attack that eventually touched over 600 organizations globally. The 2025 exposure was different in kind: a cybersecurity firm found a 4TB SQL Server backup sitting publicly on Microsoft Azure, tied to an entity EY Italy had acquired. That researcher, working for Neo Security’s writeup on the exposed backup file, described the find bluntly.
Finding a 4TB SQL backup exposed to the public internet is like finding the master blueprint and the physical keys to a vault, just sitting there.
EY said at the time that no client information, personal data, or confidential EY data was affected, and that the exposure was isolated to the acquired Italian entity rather than EY’s global systems. This latest breach involves a different platform entirely, a support ticketing tool rather than a cloud storage bucket, but the underlying weakness looks familiar: sensitive client data sitting inside a third-party tool that was not built, or not secured, with that data in mind.
Why Do Help Desk Platforms Keep Becoming the Way In
Support ticket systems make appealing targets because they concentrate sensitive attachments from many clients inside one third-party environment, often with weaker controls than the systems those attachments came from. A single compromised ticketing tool can expose files spanning dozens of unrelated client relationships at once.
That dynamic is not unique to EY or to accounting firms. Attackers have increasingly gone after IT service management and helpdesk software specifically because it aggregates data by design rather than by accident. A separate campaign involving malware that hides stolen data inside HuggingFace repositories shows the same underlying pattern: attackers using ordinary, trusted-looking enterprise tools as cover for moving data out the back door.
For a firm processing tax data for financial institutions across more than 150 countries, that concentration risk is amplified. One breached helpdesk ticket can ripple outward into notifications sent by clients, and their clients, none of whom chose the vendor that got hit.
California’s Faster Clock Shaped This Disclosure
The timing of EY’s paperwork reflects a rule change most companies have not yet been tested against. California’s SB 446, signed by Governor Gavin Newsom in October 2025 and effective January 1, 2026, requires businesses to notify the state Attorney General within 15 calendar days of notifying affected consumers, whenever a breach touches more than 500 California residents, according to a law firm breakdown of California’s updated notification deadlines. EY’s consumer letter is dated July 13, 2026, and its Attorney General filing landed two days later, on July 15, comfortably inside that new window.
What the filing does not show is how long EY took to decide the incident was reportable in the first place. Nearly three months separate the April 23 detection date and the mid-July notification letters, a gap the new state deadline does not directly address since it governs the interval between consumer notice and regulator notice, not the interval between discovery and consumer notice.
EY has not said whether it will face separate notification obligations in other states or countries tied to this incident, and the full scope of who was affected remains something only EY currently knows.
Frequently Asked Questions
Is the 2026 support platform breach connected to EY’s 4TB Azure exposure from 2025?
No. EY has described them as separate incidents. The 2025 exposure involved a publicly accessible cloud backup tied to an acquired EY Italy entity, while the 2026 breach involved unauthorized access to a third-party IT service management ticketing platform used by EY’s IT support staff.
What is an IT service management platform, and why does EY use one?
An IT service management platform, sometimes called an ITSM tool, lets a company’s technology staff track and resolve internal support requests, including tickets filed by employees who need help with client engagements. EY used one to support teams handling tax-related client work, and tickets filed through it often carried attachments with client tax data.
What should someone who receives an EY breach notification letter do first?
EY’s letter directs affected individuals to enroll in the complimentary 24-month Experian identity monitoring and restoration service before the October 31, 2026 deadline. Recipients should also review recent tax filings and financial statements for unfamiliar activity, since the exposed data included information used to prepare tax filings.
Are large accounting firms required to report breaches like this to state regulators?
Yes, in states like California, any business experiencing a breach affecting more than 500 residents must file a sample notification with the state Attorney General, a requirement now bound to a strict 15-day deadline after consumer notice under SB 446, which took effect January 1, 2026.
Three incidents, three different root causes, one recurring theme: client data kept surfacing in the tools built to support EY’s own operations rather than in the systems clients think they are trusting the firm with.
-
NEWS2 months agoCall of Duty Warzone Delisted on Xbox One and PS4 June 4
-
AZURE1 month agoMicrosoft’s MAI Models Signal a Five-Year Bet on AI Independence
-
AZURE1 month agoMicrosoft IQ Gives Enterprise AI Agents a Shared Memory
-
NEWS1 month agoXbox Games Showcase 2026: Start Time, Expected Games, What to Watch
-
AZURE2 months agoAnthropic Hits $965B, and Microsoft Profits Either Way
-
NEWS2 months agoMicrosoft Build 2026 Skips Windows 12 for the AI Bet That Counts
-
MICROSOFT 3651 month agoSatya Nadella Rebukes Scout VP Over ‘Make People Addicted’ Memo
-
NEWS2 months agoModern Warfare 4 Skips Day One Game Pass, Lands Oct 23
