Ernst & Young has begun notifying clients that a third-party IT support-ticketing platform used by its internal teams was breached this spring, exposing tax-related documents that included Social Security numbers and financial account information for a number of the firm’s institutional clients.
According to EY’s notification filed with the California Attorney General’s office on July 15, 2026, an unauthorized party accessed the platform between March 28 and April 12, 2026, and downloaded documents submitted through internal support tickets. EY says it identified the anomalous activity on April 23, roughly three weeks after the access began, and has found no evidence so far that the exposed data has been misused or that any specific individuals were targeted. The firm is offering affected clients 24 months of Experian identity monitoring and restoration services, with enrollment open through October 31, 2026. No extortion or ransomware group has claimed responsibility for the incident.
The breach did not touch EY’s core client-facing systems. It hit the IT service-management platform the firm’s own support staff use to help internal teams handling tax work, a category of tool that accumulates sensitive attachments as a side effect of routine support requests rather than by design, and is rarely classified as a crown-jewel data store the way a client portal or document-management system would be. That gap matters more for large professional-services firms than the breach’s headline numbers do. As CyberTech has covered, attackers are already mapping the SaaS platforms that connect into a firm’s crown-jewel systems looking for the path of least resistance. EY’s incident shows that path does not have to run through a headline SaaS integration at all; an internal support tool that nobody inventoried as high-risk can carry the same client data with none of the same scrutiny.
Source: California Attorney General breach notification report