Ernst & Young Discloses Breach Affecting Client Data – Veri Sızıntısı

Ernst & Young Discloses Breach via Third-Party System

Auditing and consulting giant Ernst & Young has announced a data breach resulting from a cyberattack on a third-party support system. The breach reportedly exposed documents containing client tax information.

The Ernst & Young logo on a background with a cybersecurity and data breach theme.

What Happened

Ernst & Young (EY), one of the world's four largest auditing and professional services firms, has publicly disclosed a data breach affecting its clients. According to a statement from the company, cyber attackers successfully compromised a third-party support ticket system used by EY's information technology personnel. This incident once again highlights the significant and growing risks associated with supply chain and third-party vendors in the modern business landscape.

The event demonstrates that even a massive organization like EY, which reported $53.2 billion in global revenue last year and employs 406,000 people in over 150 countries, remains vulnerable to cyber threats originating from its business partners. In notification letters sent to affected clients, the company stated that it detected anomalous activity on its networks on April 23 and immediately launched an investigation. This investigation was conducted with the assistance of external cybersecurity experts.

The findings of the investigation revealed that an unauthorized third party had gained access to the said support platform between March 28 and April 12. During this period, the attackers downloaded multiple documents from the platform. The fact that the attackers remained undetected in the system for approximately two weeks means they had ample time to examine and exfiltrate the data they found, increasing the potential impact of the breach.

What Data Was Exposed

The nature of the data exfiltrated in the cyberattack is one of the most concerning aspects of the incident. According to Ernst & Young's disclosure, the documents downloaded by the attackers contained certain personal and financial data found in or used to prepare clients' tax filings. These documents, which were attached to support tickets submitted through the platform, could contain highly sensitive information.

However, uncertainty remains regarding the exact type and scope of the exposed data. Samples of the notification letters sent by EY reportedly use a placeholder for the specific data types compromised. This suggests that the data exposed may vary for each client and that the company is providing tailored information to each victim. Information typically found in tax preparation documents can include Social Security numbers, income details, bank account information, investment data, and other personal identifiers. EY, however, has not publicly detailed which specific data types were compromised in this incident.

The company states that, at present, it is not aware of any misuse of the stolen files or any further exposure of the data on the internet. Nevertheless, the compromise of such sensitive financial data inherently carries serious risks, including identity theft, targeted phishing attacks, and financial fraud.

How the Attack Occurred

Based on the available information, the attack was not directed at EY's own core systems but at a third-party software platform it utilized. The attackers breached this external system, which was used by EY's IT staff to manage client support requests. This is a common type of cyberattack known as a supply chain attack.

The investigation confirmed that the attackers had unauthorized access to the system between March 28 and April 12, during which they downloaded numerous documents. The company has not shared any technical details about the initial attack vector—that is, how the attackers first gained entry to the system (e.g., through stolen credentials, a zero-day vulnerability, or a configuration error).

Furthermore, it is not yet known which threat actor or group is behind the attack. To date, no ransomware or data extortion group has claimed responsibility for this attack on Ernst & Young. This leaves the motivation for the attack—whether for financial gain or espionage—as a matter of speculation, with no concrete evidence available.

Who Is Affected

Ernst & Young has not disclosed the exact number of clients affected by the data breach. It is also unclear whether the incident is limited to its U.S. customer base or impacts its global operations as well. The company has only stated that it is reaching out directly to potentially affected clients by mail. Therefore, if you have not received a notification, it is likely that your data was not affected by this event.

Those affected are likely individuals or corporate clients who had engaged EY for tax advisory or similar services and had shared documents via the support platform in the process. The exposure of highly confidential information like tax data can create significant privacy and security issues for both individuals and businesses.

What You Can Do

If you have received a notification letter from Ernst & Young regarding this data breach, it is important to take the situation seriously and act promptly. Here are the steps you can take:

  • Enroll in the Identity Protection Service: EY is offering affected clients 24 months of free identity monitoring and restoration services through Experian. Be sure to enroll in this service before the deadline mentioned in the letter, October 31, 2026. These services monitor for suspicious activities, such as new credit accounts being opened in your name, and alert you.
  • Be Wary of Phishing Attempts: Attackers may use the stolen information to craft highly convincing and personalized phishing emails or phone calls. Be vigilant for suspicious communications pretending to be from EY, tax authorities, or your bank. Never confirm personal information via email or phone.
  • Review Your Financial Accounts: Regularly check your bank and credit card statements for any transactions you do not recognize. If you notice any anomalies, contact the respective financial institution immediately.
  • Update Your Passwords: While not directly related to this breach, changing the passwords for your important online accounts and enabling multi-factor authentication (MFA) will enhance your overall security.

What the Company Is Saying

Ernst & Young stated that after detecting the incident, it secured its systems and terminated the unauthorized access. The company also reported the matter to federal law enforcement authorities. In the letters to clients, it noted, "we are not aware of any misuse or further exposure of the stolen files and have no indication that particular individuals were targeted by the threat actors."

By offering 24 months of Experian identity monitoring services, EY appears to be taking a proactive step to mitigate the risks arising from the incident. However, inquiries from BleepingComputer for more information about the incident had not received a response at the time of publication. It remains uncertain whether the company will release more technical details or information about the scope of the impact in the future.

Source

https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.