Ernst & Young breach exposes client tax data – find out if you’re at risk and what to do next | ZDNET

July 21, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: zdnet.com

Threat Risk: Medium
Victim: Accounting firm clients
Incident: Unauthorized access to a third-party IT support system used by Ernst & Young.
Impact: Theft of sensitive tax-related financial information from multiple clients.
Attacker: Unidentified threat actors
Analysis: The incident highlights the persistent risk of supply chain attacks through third-party support tools. Attackers gained access to a ticketing system where sensitive tax data was stored or transmitted, allowing for the exfiltration of client records over a two-week period. The gap between the initial breach and detection underscores the challenges of monitoring external service providers.
Recommendations: Implement strict data minimization policies to prevent sensitive PII from being entered into support tickets; Conduct rigorous security audits and risk assessments of all third-party IT service providers; Enable enhanced monitoring and multi-factor authentication on all external support platforms
Source: ZDNET

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *