Overview
- EY detected anomalous activity on April 23 and says attackers accessed a third‑party IT service management platform from March 28 to April 12, 2026, downloading documents tied to client tax support tickets.
- The firm says the stolen files may include names, addresses, Social Security numbers and financial account details used to prepare tax filings and that its core internal systems were not compromised.
- EY has secured the affected systems, engaged an independent cybersecurity firm, notified federal law enforcement and filed breach notices with state authorities including California.
- The company began notifying affected clients in July and is offering 24 months of Experian identity monitoring and restoration services for those contacted.
- Law firms have opened investigations into possible class actions and observers warn exposed tax records raise heightened risks of identity theft, tax fraud and targeted phishing attacks.