Ernst & Young Data Breach Exposes Social Security Numberes

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: claimdepot.com

Threat Risk: High
Victim: Customers of EY’s financial institution clients
Incident: Unauthorized access and data exfiltration from a third-party IT service management platform.
Impact: Exposure of Social Security numbers, driver’s license numbers, and financial account information.
Attacker: Unidentified threat actors
Analysis: The breach occurred due to unauthorized access to a third-party IT service management platform used for tax-related support. Attackers were able to download documents containing highly sensitive PII and financial records of individuals who were not direct clients of EY, but customers of EY’s financial institution partners. This incident emphasizes the systemic risk posed by third-party tool integration and the dangers of storing unencrypted sensitive data within support tickets.
Recommendations: Implement strict data minimization policies to prevent the storage of PII in support tickets; Enforce phishing-resistant multi-factor authentication (MFA) across all third-party vendor platforms; Conduct regular security audits and access reviews for external service providers handling sensitive client data
Source: ClaimDepot

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *