Connect with us

NEWS

EY’s Tax Files Walked Out of a Ticket Queue

EY’s 2026 breach ran through an unnamed help-desk platform where tax attachments sat in tickets, exposing investors who never hired the firm.

Published

on

Ernst & Young told clients in July 2026 that attackers downloaded tax documents from a third-party help-desk platform. The access ran from March 28 to April 12. The firm spotted odd activity on April 23, eleven days after that window closed.

The files were not pulled from a tax vault. They sat on tickets that EY’s own IT staff opened to support teams doing client tax work, then left through that queue.

Client Tax Files Sat in a Help-Desk Queue

EY’s US firm, Ernst & Young LLP, uses a third-party information technology service management platform so its IT staff can support internal tax teams. In the sample notice filed in California, dated July 13, 2026, the firm described how those tickets were built.

EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information.

Ernst & Young LLP, sample notice filed with the California Attorney General

That last sentence is the whole design flaw. When a tax workflow broke, staff attached the file the help desk needed to see. Those attachments included personal data and financial information used to prepare tax filings. The original copy may have lived in a locked tax system. The ticket copy did not.

An unauthorized party accessed that platform between March 28 and April 12, 2026, and downloaded documents tied to a number of EY clients. EY said it then hired an independent cybersecurity firm, cut off the access, and notified federal law enforcement. It also said it had no current evidence of misuse and no sign that named people were singled out.

The firm still has not named the vendor. It still has not said how the intruder first got in. A help-desk tool that holds tax PDFs is worth breaking into even when the crown-jewel systems stay dark, because the attachments already did the gathering work.

Four States Posted Counts. EY Still Has Not

EY has not published a global total. The only public headcounts sit in state filings that name residents those states require a firm to report. California posts a sample notice only when a business notifies more than 500 residents, so that filing is a floor, not a roster.

STATE FILINGS MADE PUBLIC IN JULY 2026

State Residents named Filed
Texas 873 July 17, 2026
Massachusetts 480 July 15, 2026
Vermont 13 July 16, 2026
California More than 500 July 15, 2026

Texas, Massachusetts, and Vermont add to 1,366 named residents. Add California’s “more than 500” rule and the four-state floor sits above 1,866. That figure is not the incident. It is the part of the incident that state law forced into public view, and it leaves out every other US state plus EY’s work abroad.

Letters went out dated July 13, 2026, by mail and email. The California filing landed July 15, 84 days after the April 23 detection date. EY offered affected people 24 months of Experian identity monitoring and restoration. Enrollment runs through October 31, 2026, on the Experian IdentityWorks enrollment site using the code in each notice.

A California attorney general spokesperson said the posted letter is the sample notice required when more than 500 residents are affected. That is why the California cell in the table is a threshold, not a headcount. The firm that can count a client’s basis lots still has not counted the people in its own ticket dump.

ShinyHunters Listed EY, Then Posted No Files

On July 27, 2026, the ShinyHunters extortion group added Ernst & Young to its leak site and claimed the job. The post told the firm to make contact by July 31, 2026. “Yes it was us. Now come talk to us,” the listing said. It added that if EY did not talk within the deadline, the group fully intended to release all the data and files.

The group also told a reporter it stole EY credentials through a supply-chain attack and used them against Jira, GitHub, and Microsoft Azure. It would not name the supplier. Those extra systems have not been shown. EY has not said ShinyHunters was the intruder, and it has not confirmed an extortion demand.

WHAT WE KNOW

  • Confirmed window: Unauthorized access ran from March 28 to April 12, 2026, on a third-party IT service management platform used for tax support tickets.
  • Detection lag: EY flagged anomalous activity on April 23, 2026, 11 days after the last recorded access.
  • Listing date: ShinyHunters put EY on its leak site on July 27 and set a July 31 contact deadline.

WHAT IS UNCONFIRMED

  • The actor: EY has not attributed the intrusion to ShinyHunters or acknowledged a ransom demand.
  • The extra systems: Claimed access to Jira, GitHub, and Azure remains unverified, and no sample of the ticket files has been published in public reporting.
  • The vendor: The help-desk platform is still described only as a third-party ITSM tool, with no product name.

By early August, none of the data the group claimed to hold had shown up on the leak site or in underground dumps that researchers were watching. The group kept EY under a final-warning label and said its leak kit was back online. That is pressure. It is not a publication.

A listing screenshot still gets passed around as if the files already landed. They had not, in any dump that public reporting could confirm. Treating the countdown page as the leak is how an extortion brand buys attention without proving what it holds. Google’s threat-intelligence unit has separately mapped ShinyHunters-branded crews from voice-phishing to data extortion on other jobs, often through help desks and suppliers rather than a core network smash. That pattern fits this incident’s shape. It does not prove this actor, and it does not turn a listing into a dump.

The People Who Never Hired EY

EY’s tax practice works for institutions. The people in the tickets often did not. Their names reached EY because a bank, fund, or other client sent investment and tax files in for professional work. A notice can be the first time those people learn a Big Four firm ever held their Social Security number.

State filings list a familiar bundle sitting next to those names. It is the bundle used to file taxes, open credit, and impersonate a person on a phone call to a bank.

DATA STATE FILINGS TIED TO THE TICKETS

  • Identity: Name, address, email, telephone number, date of birth, Social Security number, and driver’s license number.
  • Payment: Credit or debit card number, plus financial account codes.
  • Tax work: Financial account information used in or to prepare tax filings, and personal data tied to investment holdings with EY’s institutional clients.
  • How it arrived: Document attachments on support tickets, not a direct upload by the person named in the file.

EY said it had no sign those people were chosen one by one. That matches a ticket dump. The intruder did not need a target list. The help desk had already stacked the files. For anyone who holds an investment account at a firm that uses EY for tax work, the live question is whether a support ticket ever carried their return package, not whether they ever emailed EY.

Federal tax law treats that class of data as more than ordinary customer records. The IRS’s Section 7216 rules for preparers make it a crime for a return preparer to knowingly or recklessly disclose tax return information, or to use it for anything other than preparing the return, unless a listed exception or consent applies. A convicted preparer may be fined not more than $1,000 or imprisoned not more than one year, or both, for each violation. A help-desk attachment is still tax return information if it was collected to prepare a filing. Parking it on a vendor ticket does not make it ordinary IT debris.

Why Support Tickets Keep Getting Hit

Support platforms concentrate other people’s files because that is how a ticket gets solved. A tax software glitch, a stuck e-file, or a mapping error is faster to fix when the clerk can see the PDF. The same habit shows up in every large shop that runs ServiceNow, Jira Service Management, Zendesk, or a cousin: logs, screenshots, IDs, and spreadsheets land in the queue, then stay there after the ticket closes.

Attackers have learned to prefer that pile. A core tax system is monitored. A help-desk tenant is treated as plumbing. One set of vendor credentials, or one supply-chain foothold, then reaches attachments from many clients at once. Discord’s Zendesk case in 2025 followed the same shape, with ticket attachments as the haul. So do the vishing jobs that trick a help-desk agent into blessing a connected app. The door is the support process. The prize is whatever the process was allowed to hold.

EY already had two edge failures in that vein. The 2023 MOVEit Transfer mass exploit hit the firm’s file-transfer path and, per EY’s own later notice, reached personal data on more than 30,000 people, including Bank of America customers. In October 2025, researchers at Neo Security found a 4-terabyte SQL Server backup tied to EY’s Italian entity sitting open on Azure; EY said that copy was localized, cleaned up, and held no client or personal data. The 2026 ticket incident is the third time in three years the problem sat next to the work, not inside the system built for it, the same sequence already mapped as EY’s third security lapse in three years.

The claimed Azure piece of the ShinyHunters story is still only a claim. Even as a claim it points at the same lesson the Italian backup made concrete: cloud and vendor edges are where this firm keeps getting found. A tax PDF should not be sitting in any of those edges waiting for a reset-password ticket.

The July Complaint in Manhattan

Plaintiffs did not wait for the leak deadline. On July 20, 2026, Illinois resident Markishi Wyatt filed a proposed class action against Ernst & Young LLP in the U.S. District Court for the Southern District of New York, case number 1:26-cv-06108. The complaint says the firm failed to protect tax and financial information on the IT support platform. It estimates the class in the tens or hundreds of thousands. That estimate is the plaintiff’s, not a count EY has adopted, and the docket had not produced a certified class or a finding of liability.

The complaint also recites that EY employs more than 400,000 people in more than 150 countries. Scale is not the same thing as a victim count. It is the reason a single unnamed ticket vendor can touch people who never signed an EY engagement letter.

THE SPRING-TO-SUMMER CLOCK

  1. March 28, 2026: Unauthorized access to the third-party support platform begins.
  2. April 12, 2026: The recorded access window ends; documents have been downloaded.
  3. April 23, 2026: EY detects anomalous activity and opens an incident response.
  4. July 13, 2026: Notice letters go out by mail and email.
  5. July 15 to 17, 2026: Filings land in California, Massachusetts, Vermont, and Texas.
  6. July 20, 2026: Wyatt files the proposed class action in Manhattan.
  7. July 27 to 31, 2026: ShinyHunters lists EY and runs out its stated contact deadline without a confirmed public dump.

Anyone who received a July 13 letter still has the Experian window through October 31, 2026, and can freeze credit files, watch tax transcripts, and treat unexpected calls about investments as suspect. The monitoring does not unsay the attachment. It watches for what a stolen return package is good for: new credit, refund fraud, and a convincing lie to a bank.

EY still has not named the platform that held the files, and it still has not said how many people were in them. Until those two facts move, the help-desk queue remains the only complete inventory, and it is in someone else’s hands.

Disclaimer: This article is news reporting and analysis of public notices, state filings, and related claims. It is informational only and is not legal advice, identity-theft counseling, tax advice, or a recommendation to join or avoid any lawsuit. Readers who received a notice, who hold accounts at an institution that uses EY for tax work, or who are considering a claim should consult a licensed attorney and, for credit or fraud issues, a qualified credit counselor or the IRS identity-theft channels before acting. Counts, deadlines, enrollment codes, and case status come from the filings and notices described above and can change as more states are notified or as the Manhattan docket moves.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending