Ernst & Young reveals data breach following hack on support system


Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data.

In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform that helps EY staff support the teams that perform tax-related work for clients. Therefore, the tickets submitted through this platform sometimes also contain documents with client tax information which may have been exposed in the incident.

EY then activated its incident response protocols, bringing in third-party cybersecurity experts, as well as notifying relevant authorities and affected clients.

Read more…
Source:  Tech Radar


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Hacker accessed PowerSchool’s network months before massive December breach

    March 10, 2025

    A hacker compromised the U.S. edtech giant PowerSchool months before its ‘massive’ data breach in December, according to a now-published forensic report into the incident conducted by U.S. cybersecurity firm CrowdStrike. In a letter sent to affected customers last week, seen by TechCrunch, PowerSchool confirmed that an investigation into the incident has revealed that its network ...

  • Allstate sued for not reporting data breach of 165,000 New Yorkers

    March 10, 2025

    New York state sued Allstate on Monday, accusing the insurer’s National General unit of failing to report a data breach that exposed drivers’ license numbers, and not developing reasonable safeguards to protect policyholders’ private information. The lawsuit by New York Attorney General Letitia James was filed in a state court in Manhattan, and seeks civil fines. ...

  • Japanese telco giant NTT Com says hackers accessed details of almost 18,000 organizations

    March 10, 2025

    Japanese telecom giant NTT Communications (NTT Com) has confirmed that hackers accessed the data of almost 18,000 corporate customers during a February cyberattack, affecting an as-yet-unknown number of individuals. The Tokyo-based NTT Com, which provides phone and network tech to enterprises, said it discovered the data breach on February 5 after determining that the hackers had ...

  • UK: Healthcare staff illegally accessed medical records belonging to the Nottingham attack victims

    March 6, 2025

    The families of the Nottingham attack victims have said claims healthcare staff illegally accessed medical records belonging to their loved ones are “sickening” and “inexcusable”. Barnaby Webber and Grace O’Malley-Kumar, both 19, and Ian Coates, 65, were stabbed to death by Valdo Calocane in the city in June 2023. Dr Manjeet Shehmar, medical director at Nottingham ...

  • Hacked health firm HCRG demanded journalist ‘take down’ data breach reporting, citing UK court order

    March 6, 2025

    A U.S.-based independent cybersecurity journalist has declined to comply with a U.K. court-ordered injunction that was sought following their reporting on a recent cyberattack at U.K. private healthcare giant HCRG. Law firm Pinsent Masons, which served the February 28 court order on behalf of HCRG, demanded that DataBreaches.net “take down” two articles that referenced the ransomware ...

  • Bank of Ireland to pay €350K over alleged data breach that saw woman stalked by her father

    March 5, 2025

    The High Court has ordered Bank of Ireland to pay a €350K settlement to a woman and her partner, who alleged her data was released to her estranged father, who then used it to find the couple abroad and stalk them. At the High Court today, Ms Justice Mary Rose Gearty was told the settlement, which ...