The EY 2026 data breach resulted from unauthorized access to a third-party service-management platform that Ernst & Young used to support tax work performed for clients. According to the company's notification, intruders accessed the platform between March 28 and April 12, 2026 and downloaded client documents. EY detected anomalous activity on April 23, 2026.
Support requests submitted through the platform could include documents containing client tax information. EY confirmed the event through notices filed with US state authorities but did not publish a total number of affected people or clients. The count in this LeakData record is therefore unknown, and resident subsets reported by different states should not be added together as though they represented a global total.
Confirmed Types of Data
Depending on the document, downloaded information could include a person's name, address, Social Security number, financial account number, and credit or debit card number. EY also reported that other personal and financial details used to prepare tax filings may have been involved. This entry lists only those classes supported by the company and regulatory notifications.
The company did not say that every client document contained every field. Passwords, biometric data, and medical records were not part of the described scope and are not added as data classes. The combination of a Social Security number, financial accounts, and tax information nevertheless creates serious exposure to identity theft, fraudulent tax returns, new-account fraud, and targeted financial scams.
The Third-Party Platform's Role
The breach involved an external service-management platform used for tax-support requests rather than EY's main public website. Ticketing systems may collect screenshots, attachments, and detailed client context, which can make an ordinary-looking help request much more sensitive than expected. The incident shows why support attachments need data classification, retention controls, and access protection comparable to primary business systems.
EY did not disclose how the attacker first entered the platform, name a vulnerability, or identify a responsible threat actor. There is also no confirmed report that a known ransomware or extortion group claimed the event. This record does not speculate about the attack method and stays within the verified facts about platform access, the date range, and downloaded documents.
Tax and Financial Fraud Risk
Tax documents can combine employer, income, account, and identity details in one place. An attacker could use them to file a fraudulent tax-refund claim, write highly convincing messages with authentic client information, or impersonate a tax adviser. If you receive an unexpected tax-agency notice, duplicate-return warning, or refund request that you do not recognize, dispute it promptly through the tax authority's official channel.
People whose card or bank-account number was affected should contact the financial institution using the known number for the card or account. Enable transaction alerts, examine even small test charges, and replace the card or account when the institution recommends it. Those whose Social Security number was involved should consider free freezes at all three credit bureaus and any additional identity-protection option offered for their tax account.
EY's Response and Monitoring Offer
EY said it activated incident response, remediation, and recovery after identifying the anomalous activity and engaged an independent cybersecurity firm to investigate the nature and scope. As of the notification, the company said it was unaware of misuse or further exposure of the affected personal information. That statement does not mean there is no risk; it reports only that misuse had not been confirmed at that time.
Eligible affected people were offered two years of free credit monitoring, identity monitoring, and identity-restoration services. Recipients should enroll using the link and code in their own notice rather than entering a Social Security number on a page reached through a search advertisement or unexpected message. Monitoring does not replace regular review of existing accounts, statements, and tax records.
Fraudulent EY and Support Messages
Someone holding downloaded support documents may impersonate an EY professional using a correct project, client, tax-period, or account detail. A message containing real information is not necessarily from the genuine sender. Verify requests to upload a new document, change banking details, enable remote access, or share a one-time code through a separate channel with a known EY contact instead of replying to the message.
Treat messages about “breach compensation,” “activate free monitoring,” or “resubmit your tax file” with particular caution. Do not enable macros in attachments and inspect the full domain character by character. Within a client organization, coordinate the review across tax, legal, finance, and security teams because a single stolen support attachment may contain secrets belonging to several departments.
How to Interpret This LeakData Record
The zero shown here does not mean that nobody was affected; it means EY did not release a verified total number of people or records. No client documents or individual rows were imported into LeakData, so the absence of an email-search match cannot prove that a person was outside the incident. Direct recipients should rely on the data types identified in their individual EY notice.
This record covers only the March 28–April 12, 2026 access to the third-party support platform and is separate from other EY cyber events. Counts released for residents of particular states should not be treated as a worldwide total. If EY or authorities later identify a definitive person count, platform provider, intrusion method, or additional data class, the entry should be updated only to reflect that newly verified evidence.