← BACK TO FEED
data breachErnst & Youngtax datathird-party riskidentity theft

EY Breach Exposes Client Tax Data Including SSNs and Card Numbers

Ernst & Young (EY) has begun notifying clients of a data breach involving a third-party service management platform used for tax-related work, with hackers gaining access between March 28 and April 12 after the incident was discovered on April 23. The compromised data includes sensitive personal and financial information such as names, addresses, Social Security numbers, and credit/debit card numbers. EY states it is unaware of any misuse of the data and is offering affected clients two years of free credit monitoring and identity protection services.

Ernst & Young is writing to clients to inform them their personal and financial data was swept up in a breach of a third-party platform the firm uses for tax-related work.

The breach was discovered on April 23. According to a notification letter filed with the California Attorney General's Office, the compromised system is a service management platform where support tickets — often containing client tax documents — are submitted and processed.

The attackers had access between March 28 and April 12. During that window, they downloaded client documents containing a fairly alarming range of data: names, addresses, Social Security numbers, account numbers, credit and debit card numbers, and whatever else happens to end up in a tax filing package.

EY says it spotted anomalous activity, triggered incident response, and brought in an external cybersecurity firm to scope the damage. Standard playbook stuff.

As for what actually happened and who's responsible, EY isn't saying. No ransomware or extortion group has publicly claimed the attack, which doesn't tell us much either way.

The company maintains it has no evidence the stolen data has been misused. Affected clients are being offered two years of credit monitoring, identity monitoring, and identity restoration services — the customary consolation prize after this kind of incident.

SecurityWeek reports it has contacted EY for further details.

READ NEXT
23 Million Paidwork Users' Data Dumped Online After Alleged March BreachNichirei Cyberattack Leaves Japan's Frozen Food Chain on IceAccenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys