Accounting giant Ernst & Young has confirmed a significant data breach affecting its tax clients. Attackers spent two weeks inside a third-party IT support platform used for tax filings between late March and mid-April 2026.
The compromised system held sensitive client documents containing personal and financial information, including Social Security numbers. EY discovered the unauthorized access on April 23rd, but client notifications did not begin until July.
The firm emphasizes its own core internal systems were not breached. The vulnerability existed solely within a vendor's support ticket infrastructure. EY engaged an independent cybersecurity firm, shut down the attack vector, and has since secured its systems.
The incident has triggered regulatory filings with state attorneys general and prompted investigations by multiple law firms for potential class-action litigation. EY is one of the Big Four firms responsible for auditing a vast number of public companies globally.
While the breach did not involve cryptocurrency or blockchain systems, it serves as a critical case study on third-party vendor risk. For the fintech and digital asset sectors, where EY is an active advisor, the event highlights the persistent challenge of securing data in an increasingly digitized and interconnected service ecosystem.