Executive Summary
Ernst & Young LLP (EY), a Big Four professional-services firm, notified individuals and state regulators that an unauthorized third party accessed a third-party information technology service management (ITSM) / support-ticket platform used by EY IT personnel to support teams performing tax-related client work, and downloaded documents pertaining to a number of EY clients.
According to EY’s notice language (as reported by BleepingComputer, SecurityAffairs, SecurityWeek, and California Attorney General filings):
- Unauthorized access and document downloads occurred between 2026-03-28 and 2026-04-12.
- EY identified anomalous activity on the platform on 2026-04-23, initiated incident response, engaged an independent cybersecurity firm, contained unauthorized access, and stated that systems were secured.
- Individual notice letters began around 2026-07-13; EY submitted a sample breach notification to the California Department of Justice on 2026-07-15 (breach dates listed as 2026-03-28 and 2026-04-23).
- Additional state filings followed, including Vermont (2026-07-16) and Texas (2026-07-17). Public state-level counts commonly cited include Texas 873, Massachusetts 480, and Vermont 13; California’s count is unpublished but the AG’s sample-notice practice implies more than 500 California residents—yielding a four-state minimum greater than 1,866 individuals. EY has not disclosed a global total.
- Data types referenced in state notices and reputable coverage include documents in or used to prepare tax filings, and—per SecurityWeek citing EY’s Texas AGO notice—names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other tax-filing information.
- EY offered 24 months of identity monitoring and restoration via Experian, with enrollment urged by 2026-10-31; notified federal law enforcement; and stated it was not aware of misuse or further exposure and had no indication that specific individuals were targeted (at notification time).
The ITSM / support-ticket vendor has not been publicly named. No CVE has been identified as tied to this incident. No public indicators of compromise (hashes, IPs, domains) have been published as of this advisory.
On 2026-07-27, the actor brand ShinyHunters listed EY on a leak site and claimed responsibility, alleging supply-chain credential theft and access to Jira, GitHub, and Azure, with a threatened publish-by date of 2026-07-31. EY has not confirmed the claim; BleepingComputer stated it could not independently verify actor claims. As of ComplexDiscovery’s check on 2026-07-31 (~10:30 ET), no credible confirmed publication was reported. Later ~900 GB “leak” claims on lower-tier aggregators remain unverified by EY or tier-1 outlets as of 2026-09-14 and are not treated as confirmed facts in this advisory.
Core TPRM takeaway: the confirmed compromise path is a trusted third-party IT support / ITSM ticket platform that held sensitive client tax attachments—a classic third-party aggregation / shadow-archive risk for professional-services firms and any organization that attaches regulated data to helpdesk tickets.
Technical Information
This event is framed as unauthorized access to a third-party ITSM / support-ticket platform and exfiltration (download) of documents from that platform—not as a named CVE patching story, and not as a confirmed malware or ransomware campaign.
EY described a “third-party information technology service management platform” used by EY IT to support tax-related client work. The vendor name has not been disclosed.
Confirmed public timeline:
- 2026-03-28 — start of unauthorized access.
- 2026-04-12 — end of the download window.
- 2026-04-23 — EY detects anomalous activity.
- 2026-07-13 — individual notices begin.
- 2026-07-15 — California OAG sample-notice filing.
- 2026-07-16 — Vermont filing.
- 2026-07-17 — Texas filing (873 residents).
- 2026-07-27 — ShinyHunters claim (unverified).
- 2026-07-31 — no confirmed dump as of ComplexDiscovery’s check.
MITRE ATT&CK mappings below are Rescana-aligned to confirmed facts only; they are not EY-confirmed:
This advisory does not invent indicators of compromise or APT attribution.
Affected Product Versions
N/A — no named ITSM product or build has been disclosed. The named victim organization is Ernst & Young LLP.
Workaround and Mitigation
- Inventory ITSM / helpdesk platforms that can receive attachments.
- Restrict or ban tax, PII, and card attachments on tickets; keep that data in systems of record with DLP.
- Use short retention and purge sensitive attachments on ticket close.
- Enforce MFA and least privilege; limit bulk download and export.
- SOC-monitor for anomalous downloads (access closed ~11 days before detection in this case).
- Require contractual naming of the ITSM vendor and subprocessors; breach SLAs; SOC 2.
- Tabletop a vendor-ITSM compromise, including fourth-party paths.
- For notified individuals, treat Experian-style monitoring enrollment windows as time-bounded (here, urged by 2026-10-31).
Indicators of Compromise
No public indicators of compromise have been published as of this advisory. Organizations should treat that as an honest empty set and validate any future indicators before enforcement—not as proof of non-compromise.
References
- BleepingComputer, “Ernst & Young discloses data breach after support system hack,” 2026-07-17 — https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
- BleepingComputer, “Ernst & Young data breach claimed by ShinyHunters extortion gang,” 2026-07-27 — https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/
- SecurityAffairs, “Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets,” 2026-07-17 — https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html
- California Department of Justice, sample breach notification sb24-626542 — https://oag.ca.gov/ecrime/databreach/reports/sb24-626542
- SecurityWeek, “Ernst & Young Data Breach Affects Personal, Financial Information,” 2026-07-20 — https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-information/
- SecurityWeek, “ShinyHunters Claims Ernst & Young Hack,” 2026-07-29 — https://www.securityweek.com/shinyhunters-claims-ernst-young-hack/
- ComplexDiscovery, “ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach,” 2026-07-31 — https://complexdiscovery.com/shinyhunters-july-31-deadline-for-ey-arrives-after-third-party-tax-data-breach/
Third-Party Risk Bridge: Helpdesk ITSM as a Shadow Archive
Helpdesk and ITSM queues became a shadow archive of client tax and PII. A trusted-relationship compromise of the support platform bypassed the core perimeter. Inventory ITSM tools; ban sensitive attachments; require MFA; purge retention; tabletop the scenario; and require named vendors and breach clocks.
Book a demo to see how Rescana maps third-party ITSM and helpdesk platforms that can hold regulated attachments, and whether vendor access, retention, and bulk-download controls are evidenced before residual third-party risk is closed.
Forward this advisory to your TPRM owner if client tax or financial documents are allowed on IT support ticket platforms.



