EY Confirms Data Breach in Third-Party Platform and Notifies Four U.S. States About Clients' Tax Data

The Big Four firm admits to a breach between March 28 and April 12 in a third-party IT service management platform. Tax data and clients' financial information exposed. Notifications sent to four states; U.S. office offers 24 months of Experian monitoring.
Ernst & Young announced this week to consumer protection authorities in California and Vermont that it suffered a data breach in a third-party IT service management platform used by its tax services practice. The notification to the California Attorney General was filed on July 15, and the one for Vermont on July 16. TechTimes reported on July 19 that four U.S. states have been notified so far, and letters to those affected began to be sent out on July 13. This marks the second of the Big Four to acknowledge a third-party incident in July, following Accenture's confirmation of a breach on July 7.
The EY statement, replicated by Bleeping Computer and Cybernews, outlines the timeline: unauthorized access to the platform occurred between March 28 and April 12, internal detection on April 23, containment in the following days, and an investigation conducted by an independent forensics firm. According to the EY's statement, the exposed data includes names, addresses, dates of birth, Social Security numbers, driver's license numbers, banking information, and information used to prepare tax returns. The company is offering 24 months of Experian IdentityWorks monitoring with registration open until October 31.
What Has Not Yet Been Confirmed
EY did not disclose the name of the IT service management platform provider, nor the exact number of affected clients, or whether any threat actor has publicly claimed responsibility for the incident. No ransomware group had listed EY on a leak site by the time of publication. The firm also did not indicate if clients' data outside the United States was accessed, despite the tax services practice operating in an integrated manner across the U.S., the UK, India, and Brazil via a global shared services model.
Classaction.org and the Edelson Lechtzin law firm have already begun investigating for a potential class action, a typical movement in the post-notification cycle in the United States that often pressures the timeline for additional disclosures.
The Quarterly Pattern Among the Big Four
EY is the second among the Big Four to admit to a breach in July. Accenture confirmed on July 7 that an actor was selling 35 GB of source code, RSA and SSH keys, Azure Personal Access Tokens, and storage keys. The pattern in both cases is similar: the vector enters through the supplier layer or identity surface, putting the consulting firms in the atypical position of victims, rather than being responsible for the victim. According to Wendi Whitmore, former Unit 42, who spoke with SecurityWeek in a panel weeks ago, the market for outsourced support used to provide audit and tax services "has turned into a vector of systemic risk that the governance of the auditors themselves struggles to map."
The analogy with last year's Snowflake incident, which affected AT&T and other clients, is limited. In this case, there is no public evidence of reused credentials or infostealers. EY's public disclosure, unlike the pattern observed in the last cycle, occurred before any publication on leak sites, suggesting a detection route via internal means or an engaged partner, rather than external whistleblowing.
Reading Beyond the United States
In the UK, the Information Commissioner's Office has yet to confirm receipt of a separate notification, but the deadlines under the UK GDPR require communication within 72 hours if data of British residents were affected. EY UK has one of the largest tax practices in the European market and operates on the same platform backbone as the American firm.
In India, home to several of EY's Global Delivery Centers, CERT-In requires notification within six hours for incidents of a certain category, a shorter timeframe than any other relevant jurisdiction. There is no public indication that EY contacted CERT-In regarding this incident.
In Brazil, the LGPD mandates communication to the ANPD and affected individuals within a reasonable timeframe, without a fixed number. EY Brazil is part of the Global Tax Practice that experienced the breach, but the firm has yet to confirm whether data from local clients was accessed. Compliance lawyers interviewed by Brazilian outlets in the second quarter have warned that the number of third-party notifications reaching the ANPD is expected to rise in the coming months, as cases like EY's make the shared services vector public.
For the CIO of any large audited firm, the EY incident has practical implications today. Audit and tax consulting contracts often contain clauses requiring notification within 24 hours of any intrusion in the vendor environment that may expose sensitive data. The notifications from July will compel legal teams to demand formal proof of platform segregation between Big Four firms and their IT service management providers, something that, in most existing contracts, is currently stated and not audited.