Particle.news

EY Breach Exposes Client Tax Documents After Hack of Third‑Party Support Platform

The exposure raises identity and tax‑fraud risks, prompts client notifications, offers of Experian monitoring, potential regulatory scrutiny

Overview

  • Ernst & Young says an unauthorized actor accessed a third‑party IT service management platform and downloaded tax‑related support tickets and attached documents between March 28 and April 12, 2026, after detecting anomalous activity on April 23, 2026.
  • In July 2026 EY began notifying affected clients, filed a notice with the California Department of Justice, removed the unauthorized access, secured systems, and told federal law enforcement about the incident.
  • EY is offering 24 months of free identity monitoring and restoration through Experian to impacted customers as a mitigation step.
  • Key details remain undisclosed: EY has not said how many clients were affected, which third‑party vendor’s platform was compromised, or who the threat actor is, and no extortion group has publicly claimed responsibility.
  • The incident highlights third‑party supply‑chain risk for large professional‑services firms and raises real risks of identity theft, tax fraud, and phishing for affected people, with one law firm already investigating potential class‑action claims and prior October 2025 vendor exposures adding regulatory context.