Ernst & Young data breach exposes client tax information

This digest was compiled by AI from multiple sources — links to the originals are below.
Ernst & Young disclosed a data breach that exposed client tax-related information. Attackers accessed a third-party support ticket system from March 28 to April 12. The firm began notifying affected customers on July 15.
The Breach
Ernst & Young detected suspicious activity on a third-party IT platform on April 23. The platform, used for tax-related support tickets, had been compromised for two weeks. A cybersecurity firm was hired to investigate, and the system has since been secured.
Data at Risk
The stolen data includes financial information used in tax filings, such as names, addresses, and Social Security numbers. Ernst & Young has not disclosed the exact records leaked or the number of affected clients. The firm stated it is not aware of any misuse of the information.
Client Notification
Ernst & Young filed breach notices with California, Massachusetts, and Vermont. Affected clients are receiving letters detailing the compromised data. The firm is offering 24 months of free credit monitoring and identity restoration services through Experian.
ShinyHunters Extortion Gang Claim
The ShinyHunters extortion gang has claimed responsibility for the Ernst & Young data breach. According to the group, the intrusion originated from a supply-chain attack that compromised multiple key EY systems. The firm has not publicly verified the claim.