Ernst & Young (EY), one of the world’s Big Four professional services firms and a major player in privacy and cybersecurity consulting, has disclosed a data breach involving a third-party IT support ticket system. The incident, which occurred between late March and mid-April 2026, potentially exposed client tax documents and related personal and financial information.
This breach serves as a high-profile reminder that even organizations at the forefront of privacy advisory services are not immune to third-party risks — and that robust vendor management remains a critical component of any effective privacy program. This is on the heels of numerous law firms telling us how they have threat actors sending out Microsoft Teams meetings with suspicious activity as it only takes one person internally for the breach to happen.
Details of the EY Breach
According to EY’s notification, the company uses a third-party information technology service management platform to support its internal IT teams handling tax-related client work. Support tickets on this platform sometimes included documents containing client tax information.
EY detected anomalous activity on April 23, 2026, and promptly launched an incident response. Working with an independent cybersecurity firm, the company determined that an unauthorized third party had accessed the platform between March 28 and April 12, 2026, and downloaded documents related to a number of clients.
The compromised information included personal and financial data used in or contained within tax filings. EY has stated it has no evidence of further exposure or specific targeting of individuals, and it has secured its systems. The firm is offering affected clients 24 months of identity monitoring and restoration services through Experian.
As a firm with approximately 406,000 employees and global revenues exceeding $53 billion, EY’s access to sensitive client data across audit, tax, consulting, and advisory services makes it a particularly attractive target and even more than law firms like Wilmer Hale who recently had to deal with an incident like this as well as internal threats like Hugging Face breach at OpenAI by their own systems… So in short there are security and data privacy landmines everywhere. Even the GDPR isn’t immune as they fined themselves for a privacy violation.
Why This Incident Matters for the Privacy Industry
EY is widely recognized for its privacy consulting expertise, helping clients navigate complex regulatory environments including CCPA/CPRA, GDPR, and emerging state laws. The fact that a data breach occurred within its own ecosystem underscores a fundamental truth: third-party risk is universal.
Even organizations that advise others on privacy and cybersecurity can fall victim when vendor controls or oversight gaps exist. This incident highlights several key lessons:
- Third-Party Platforms Are High-Risk Vectors — Support ticket systems often contain unstructured sensitive data (documents, attachments, client details) that may not receive the same level of scrutiny as core production systems.
- Detection and Response Timing Matters — The access window spanned roughly two weeks before detection. Faster anomaly detection through advanced monitoring can significantly limit impact.
- Transparency and Client Support Are Critical — EY’s proactive notification and offering of credit monitoring services help maintain trust, but the incident still creates potential reputational and contractual ripple effects.
Broader Implications and Compliance Takeaways
This breach reinforces the need for rigorous third-party risk management (TPRM) programs, particularly for organizations handling sensitive financial or tax data. Key recommendations include:
- Map and Inventory Vendors — Maintain a complete inventory of all third-party platforms, especially those that may store or process client data in unstructured formats.
- Conduct Thorough Due Diligence — Regularly assess vendors’ security practices, incident response capabilities, and data handling procedures. Include specific questions about support ticket security and document storage.
- Implement Strong Contractual Protections — Ensure agreements include clear data protection obligations, audit rights, breach notification timelines, and appropriate insurance or indemnity provisions.
- Apply Technical Controls — Where possible, minimize sensitive data in support tickets, use encryption, and implement strict access controls and monitoring.
- Test Incident Response — Regularly simulate breaches involving third-party systems to ensure detection and notification processes work effectively.
- Plan Client Communications — Have templated notification language and support offerings ready to maintain trust and meet regulatory timelines.
For privacy consultancies themselves, this incident is a powerful case study to share with clients — demonstrating that vendor risk management must be continuous and multilayered.
FAQs on the EY Breach and Third-Party Risk
Q: How many clients were affected?
A: EY has not publicly disclosed the exact number. Notifications are being sent to impacted clients, and the firm is offering identity monitoring services.
Q: Was this a ransomware attack?
A: No ransomware group has claimed responsibility, and EY has not indicated that data was encrypted or held for ransom. The breach appears focused on unauthorized access and data exfiltration.
Q: What should clients do if notified by EY?
A: Review the notification carefully, enroll in the offered monitoring services, monitor accounts for suspicious activity, and consider additional protective steps such as freezing credit if appropriate.
Q: Does this affect EY’s credibility as a privacy advisor?
A: Incidents like this highlight that no organization is immune. How EY responds — through transparency, remediation, and lessons learned — will be key to maintaining client confidence.
Third-Party Risk Demands Vigilance
The EY breach is a sobering reminder that even leading privacy and cybersecurity consultancies must continuously strengthen their own vendor oversight. For all organizations, third-party risk management is not a checkbox exercise — it is an ongoing program that requires clear ownership, robust processes, technical controls, and regular testing.
As data breaches involving support platforms and other vendors continue to surface, businesses should treat vendor security as an extension of their own privacy and security programs. Proactive investment in strong TPRM practices is far less costly than the reputational, regulatory, and client impact of an incident.
Stay informed on data breach trends, third-party risk management, and privacy compliance best practices with Captain Compliance and book a demo below for a free data privacy audit for your organization.