GoFirm
Back to Blog
Case Studies·4 min read

Why did Ernst & Young take 26 days to notice its support desk was leaking client tax returns?

By GoFirm

On 23 April 2026, Ernst & Young LLP (EY), one of the world's four largest professional services firms, detected anomalous activity on a third-party information technology service management platform used by its tax practice. The platform exists to let EY's own IT personnel field support tickets from staff working on client tax engagements, and those tickets routinely carried attachments: documents containing client tax filings, financial account details, and personal information. By the time EY noticed anything wrong, an unauthorised third party had already been inside the platform for weeks.

According to the notification letters EY began sending on 13 July 2026, the unauthorised access ran from 28 March to 12 April 2026, a window of sixteen days during which the intruder downloaded multiple documents belonging to a number of EY's tax clients. EY has not disclosed how the platform was compromised, whether through a stolen credential, a phishing attempt against IT support staff, or a flaw in the vendor's own software. What is confirmed is the outcome: for eleven days after the access ended, and twenty-six days after it began, nobody at EY or its third-party vendor noticed that client tax records were leaving the building.

EY's own account of its response reads as textbook incident handling. It engaged an outside cybersecurity firm, notified federal law enforcement, secured the platform, and filed breach notifications with the California Attorney General on 15 July and Vermont regulators the following day. It is offering affected clients 24 months of Experian IdentityWorks credit monitoring, with enrolment open until 31 October 2026. None of that changes what happened in the sixteen days that mattered: a firm with 406,000 employees and $53.2 billion in annual revenue, whose entire business is auditing other organisations' financial controls, could not say who took its own clients' tax data, or when, until weeks after the fact.

EY has not disclosed how many individuals are affected, which third-party vendor operated the compromised platform, or the full categories of data exposed for each client. A sample notification filed with Vermont regulators lists Social Security numbers, financial account codes, and credit or debit account information among the data types that may be involved. No extortion group has claimed the breach, and EY says it has no evidence the stolen files have been misused, but tax data sitting unclaimed and unconfirmed on somebody else's server is not the same as tax data that was never taken. It is the third disclosure this year in which a support or survey tool run by an outside vendor, rather than a company's core network, became the route out for sensitive records.

The defences that failed here were not weak by conventional standards. EY is a firm built on assessing other organisations' internal controls, with security resourcing that few of its own clients could match. What it did not have was a control on the one action that mattered: the download of bulk client documents from a support platform used by IT staff. Once that platform accepted the request, the documents left. Nothing sat at that moment asking whether a named person at EY had actually authorised the export.

A bulk document download from a client-data-bearing platform is an execution event. Before it can complete, a real-time push notification goes to the named authority responsible for that platform, the engagement partner, the data custodian, whoever holds the accountability, requiring biometric confirmation on their registered device before the export is allowed to proceed. If that confirmation does not arrive, the download is blocked, regardless of whether the credentials making the request are valid.

This is the distinction that would have mattered in EY's case. Valid access to a support ticket platform is not the same as authorisation to remove sixteen days' worth of client tax filings from it. A compromised credential, however convincingly it authenticates, cannot produce a biometric confirmation on the named authority's own device through a separate channel. The execution boundary holds regardless of how the access was obtained.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence
. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Toulas, B. 2026. Ernst & Young discloses data breach after support system hack. BleepingComputer, 17 July 2026.
2. Ćemanović, A. 2026. EY says client tax data exposed in third-party IT software breach. CyberInsider, 17 July 2026.
3. Ernst & Young. 2026. Notice of Data Security Incident (sample notification letter filed with the California Attorney General). 13 July 2026.

Share this article