Hackers Breach EY's Third-Party IT Support Platform, Steal Client Tax Documents

Ernst & Young has confirmed a breach of a vendor managed IT support platform, exposing client tax documents including Social Security numbers and financial account information.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Corporate office workstation representing a third-party vendor data breach exposing client tax documents

Corporate office workstation representing a third-party vendor data breach exposing client tax documents

Ernst & Young LLP, one of the world's Big Four professional services firms, has disclosed a data breach in which an unauthorised third party infiltrated a vendor managed IT service platform and exfiltrated documents containing client tax data.

Where the exposure actually happened

EY relies on a third-party IT service management platform that its internal technology personnel use to support teams handling tax related client engagements. Support tickets logged through the system frequently included attached documents containing sensitive client tax information, which is precisely what made the platform a high value target despite sitting outside EY's core network. This is the same category of exposure we detailed in our coverage of Microsoft's mapping of the year-long ShinyHunters campaign against Salesforce, where attackers repeatedly found it easier to walk in through a trusted third-party integration than to break the core platform itself.

A month long detection gap

EY first flagged anomalous activity within the platform on 23 April and immediately activated its incident response procedures. Working with an independent cybersecurity firm, the company later determined that the actual intrusion window predated detection by nearly a month, with unauthorised access and document downloads occurring between 28 March and 12 April. That gap gave the threat actor a substantial window to exfiltrate data belonging to numerous EY clients before the breach was even identified.

What was exposed

The stolen documents contained personal information tied to individuals' investment holdings maintained with EY's institutional clients, along with financial data used to prepare tax filings. A separate filing with the Vermont Attorney General's office indicated the exposure may have included Social Security numbers, financial account codes, and credit or debit account information. EY's notification letters to affected individuals use placeholder data fields, suggesting the specific categories of exposed data vary by recipient and business unit, which points to a broad and unevenly distributed exposure rather than a single uniform dataset.

Response and remaining questions

EY filed formal breach notifications with the California Attorney General's office on 15 July and with Vermont regulators the following day. The company says it has contained the incident, confirmed unauthorised access has stopped, and notified federal law enforcement. It is offering affected individuals 24 months of complimentary credit and identity monitoring through Experian IdentityWorks, with an enrolment deadline of 31 October. As of publication, no ransomware or data extortion group has claimed responsibility, and EY says it has no evidence the stolen data has been misused or that specific individuals were deliberately targeted.

A pattern, not an isolated incident

This is EY's second significant exposure incident in roughly nine months, following an unrelated 4TB cloud storage misconfiguration tied to its Italy branch discovered late last year. Taken together, the two incidents point to a firm managing exposure risk across multiple, structurally different vectors, vendor managed ticketing infrastructure in this case, cloud storage configuration in the other, rather than a single fixable weakness. This mirrors what we saw play out with Coca-Cola's Fairlife brand, where a ransomware attack on production-adjacent systems halted an entire brand's US manufacturing: the point of compromise is rarely the system an organisation considers its crown jewel. For any large professional services firm, and particularly ones handling sensitive financial and tax data across a global client base including operations throughout the GCC, this case is a useful reminder that third-party IT support and ticketing platforms deserve the same security scrutiny as core client facing systems, since attackers are increasingly targeting the support layer specifically because it sits one step removed from where organisations concentrate their strongest defences.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.