EY Breach Exposes Clients’ Tax Files, SSNs and Account Numbers

Ernst & Young notified clients that a breach discovered April 23 exposed tax files and personal data, including Social Security, bank account and card numbers.

Ernst & Young has begun notifying clients that a breach of a third-party service management platform used for tax work exposed client tax files and personal data. The firm detected suspicious activity on April 23 and reports attackers had access to the platform from March 28 to April 12.

The platform is used to manage support tickets for tax engagements. In a notification filed with the California attorney general, EY wrote: “Support tickets submitted through the platform may include documents containing client tax information.”

Filings with state regulators show attackers downloaded client documents. Those files may contain names, addresses, Social Security numbers, bank account numbers, credit and debit card numbers and other information used to prepare tax returns.

EY activated its incident response process, began remediation and recovery, and engaged an independent cybersecurity firm to investigate the scope of the intrusion. The firm has notified state authorities and is communicating directly with impacted clients through formal letters.

EY is offering two years of complimentary credit monitoring, identity monitoring and identity restoration services to affected clients. The company has reported no known misuse or further public exposure of the affected information.

EY has not disclosed how the attackers gained access to the platform or identified a responsible threat actor. No ransom demand or public extortion claim has been reported. The company continues remediation and monitoring while the investigation proceeds.

Articles by this author