EY Breach Exposes Client Tax Data Including SSNs and Card Numbers
Ernst & Young is writing to clients to inform them their personal and financial data was swept up in a breach of a third-party platform the firm uses for tax-related work.
The breach was discovered on April 23. According to a notification letter filed with the California Attorney General's Office, the compromised system is a service management platform where support tickets — often containing client tax documents — are submitted and processed.
The attackers had access between March 28 and April 12. During that window, they downloaded client documents containing a fairly alarming range of data: names, addresses, Social Security numbers, account numbers, credit and debit card numbers, and whatever else happens to end up in a tax filing package.
EY says it spotted anomalous activity, triggered incident response, and brought in an external cybersecurity firm to scope the damage. Standard playbook stuff.
As for what actually happened and who's responsible, EY isn't saying. No ransomware or extortion group has publicly claimed the attack, which doesn't tell us much either way.
The company maintains it has no evidence the stolen data has been misused. Affected clients are being offered two years of credit monitoring, identity monitoring, and identity restoration services — the customary consolation prize after this kind of incident.
SecurityWeek reports it has contacted EY for further details.