Cybersecurity

EY breach exposed tax data including Social Security numbers

Future Technology ยท 24 July 2026

Ernst and Young has confirmed that an unauthorised party broke into a third-party IT support ticketing platform used by its staff, and spent roughly two weeks downloading documents belonging to a number of EY clients before anyone noticed.

According to EY's breach notification filed with the California Attorney General on 15 July 2026, the intrusion ran from 28 March to 12 April 2026. EY says it identified anomalous activity on 23 April, more than a week after the access window closed, and immediately triggered its incident response process.

The data taken includes names, addresses, dates of birth, Social Security numbers, driver's licence numbers, email addresses, phone numbers, credit and debit card numbers, and financial account information tied to tax filings. In other words, close to everything an identity thief would need.

EY says it has no current evidence the data has been misused or that specific individuals were targeted. That is the standard line every breached company reaches for in the first notification letter, and it is worth remembering it describes what EY knows today, not what will be true in six months.

The firm is offering 24 months of free identity monitoring and restoration through Experian IdentityWorks, with an enrolment deadline of 31 October 2026.

What to do if you're affected

If you've received or expect to receive a notification letter from EY, enrol in the Experian monitoring before the October deadline. Beyond that, consider placing a free credit freeze with Equifax, Experian and TransUnion directly through their websites, not through a paid third-party service. A freeze blocks new credit applications in your name until you lift it, and it costs nothing.

Watch for phishing emails that reference the breach itself. Scammers routinely send fake 'here is your free monitoring' links after news like this breaks, and the fastest way to get scammed twice is to click one.