Decoding the world of cybersecurity

EY tax support breach exposes client data

A breach involving a third-party support platform used by EY tax teams exposed personal and financial information held in tickets and documents.

EY tax support breach exposes client data
Summary
  • EY has notified affected individuals after attackers accessed a third-party service management platform used for tax-related support work.
  • Reported notices say attackers accessed and downloaded client documents between 28 March and 12 April.
  • The breach shows how support tickets and attachments can concentrate sensitive client data outside core systems.

EY has notified affected individuals after a breach involving a third-party service management platform used to support tax-related work exposed personal and financial information.

Reported breach notices say EY detected anomalous activity in the platform on 23 April and determined that an unauthorised actor had accessed and downloaded files between 28 March and 12 April. The platform was used by EY IT staff to support teams performing tax-related work on behalf of clients.

Support tickets submitted through the platform may have included documents containing client tax information. Reported exposed data included names, addresses, Social Security numbers, account numbers, credit and debit card numbers, and other information used to prepare tax filings. EY reportedly said it is not aware of misuse or further exposure of the affected information.

The incident is currently clearest through breach notices and security reporting rather than a broad public company statement. EY has reportedly said it activated incident response processes, engaged an independent cybersecurity firm, began remediation and recovery work, and notified relevant authorities and affected clients. The full number of affected clients and individuals has not been publicly confirmed.

The breach demonstrates how sensitive data can accumulate outside formal client systems. Support platforms often hold attachments, screenshots, free-text explanations, troubleshooting notes, and documents submitted to resolve technical or operational issues. In tax, audit, legal, consulting, and managed service environments, that material can include regulated and highly confidential information.

Third-party platforms add another layer of dependency. A professional-services firm may apply strong controls to its core client systems, while support workflows depend on a separate service with its own access model, logging, retention, and integration controls. If client documents pass through that environment, the platform becomes part of the client-data control surface.

Retention and classification are central. Support tickets are useful because they preserve context, but that same persistence can turn them into shadow repositories. Documents may remain attached long after the original issue has been resolved, and access may be wider than the sensitivity of the material warrants.

Regulated clients will need to understand which documents were exposed, whether the material relates to their staff or customers, and whether any notification duties arise in their own jurisdictions. Those questions can be difficult to answer when sensitive content sits in attachments rather than structured records.

The professional-services sector concentrates trust. Tax advisers, auditors, lawyers, consultants, and outsourcing providers sit close to financial data, corporate structures, employee records, transactions, and confidential decisions. A breach affecting one support platform can therefore become a multi-client exposure event even when client systems themselves are not compromised.

Support environments need data minimisation, attachment controls, privileged access management, retention limits, encryption, monitoring, and clear breach workflows. Where client-confidential material enters a ticket queue, it should be governed as deliberately as the system the ticket was created to support.

×