Ernst & Young Reveals Data Breach After Support System Hack, Leaving Thousands of Clients Concerned
Global auditing and professional services giant Ernst & Young (EY) has disclosed a data breach that occurred when an unauthorized third party accessed its support ticket system. The compromised platform allowed hackers to download multiple documents containing sensitive client information, including personal and financial data used for tax filings.
The company detected anomalous activity on its networks on April 23 and initiated an investigation with the help of external cybersecurity experts. They determined that the breach occurred between March 28 and April 12, during which time the attackers downloaded various documents from the support ticket system. The exact type and scope of the exposed information remain unclear, as the notification sample provided by EY includes a placeholder for the specific data types.
As one of the world’s four largest auditing and professional services providers, Ernst & Young has an extensive global reach, employing over 406,000 people in more than 150 countries. The company reported $53.2 billion in revenue last year alone. With such a vast customer base, the potential impact of this data breach is significant, although EY has not disclosed exactly how many customers were affected or whether the incident was limited to its U.S. client base or occurred internationally.
EY has assured that it has secured its systems and notified federal law enforcement authorities, while also stating that there is no indication of any misuse or further exposure of the stolen files. To mitigate the risks arising from this exposure, EY offers affected clients 24 months of identity monitoring and restoration service through Experian and urges them to enroll by October 31, 2026.
While it’s unclear whether a data extortion or ransomware group is responsible for the attack on Ernst & Young, the incident serves as a stark reminder that even the largest and most secure organizations are vulnerable to cyber threats. As hackers continue to evolve their tactics and techniques, businesses must stay vigilant and proactive in protecting themselves against potential breaches.
In light of this incident, it’s essential for individuals and organizations alike to take steps to protect themselves from data breaches. This includes regularly monitoring network activity, implementing robust security measures, and staying informed about the latest cybersecurity threats. By being proactive and prepared, we can reduce the risk of falling victim to a data breach and minimize the damage when one does occur.
Source: Bleeping Computer — 2026-07-17