Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
EY Waited Three Months to Disclose a Breach That Exposed Client Tax Data

Ernst & Young, one of the world's Big Four accounting firms, has confirmed a data breach that exposed client tax information after hackers spent roughly two weeks inside a third-party IT support platform this spring.
According to breach notifications filed with the California and Texas Attorneys General on July 15, an unauthorized party accessed the system between March 28 and April 12, downloading documents attached to internal support tickets. EY says it detected the intrusion on April 23, nearly three weeks after the access began, and didn't disclose it publicly until roughly three months after that.
How It Happened
The breach didn't touch EY's core network. It hit a third-party IT service management platform that EY's help desk staff use to log and resolve technical problems, according to EY's own notification letter. Staff routinely attached documents to those tickets when troubleshooting client account issues, including files tied to tax preparation.
That turned a routine internal help desk tool into what amounted to an unintentional archive of sensitive client records. EY's notice states plainly that "support tickets submitted through the platform may include documents containing client tax information."
EY has not disclosed how the attacker got in. No ransomware group or extortion gang has claimed responsibility, and TechRadar reports the stolen data has not surfaced on the dark web so far. That means nothing has been confirmed leaked publicly yet, not that nothing was taken.
What Was Actually Taken
EY has been vague on specifics. The firm's official notice references "certain financial information contained in or used to prepare tax filings," according to ZDNET, without a full accounting of exactly which data points were exposed.
Gblock reported that the exposed documents reportedly included names, home addresses, Social Security numbers, bank account numbers, credit and debit card numbers, tax preparation files, and information tied to individuals' investment holdings with EY's institutional clients. If accurate, that amounts to close to a complete identity theft kit. EY has not confirmed this exact list in its public notices, and the company has not said how many clients total were affected.
EY maintains it has no evidence the data has been misused. The firm's notice states it is "not aware of any misuse or further exposure" of personal information and says there's no indication anyone was "specifically targeted." That's a statement of what EY has observed so far. Stolen financial and tax data can be sold or used months or years after a breach with no immediate red flags.
The Three-Month Gap
The timeline here deserves scrutiny. EY detected the intrusion April 23. It didn't file breach notices with state regulators until July 15, nearly three months later.
That gap isn't necessarily illegal. Breach notification laws vary by state, and companies routinely cite ongoing investigations, forensic work, and coordination with law enforcement as reasons for delay. EY says it brought in an independent cybersecurity firm to investigate and worked to contain the incident before notifying clients. There's no indication in these sources that EY violated any specific disclosure deadline.
But for clients whose Social Security numbers may have been sitting with a hacker since March, three months of silence is three months they couldn't watch for fraud, freeze credit, or take precautions. Companies want time to get facts straight before alarming customers, and customers want fast warning to protect themselves. EY chose to prioritize the former.
The Lawsuit
A proposed class action has already been filed, according to CFO Dive. The plaintiff, Illinois resident Markishi Wyatt, claims her information was compromised and is seeking to represent all affected U.S. individuals.
The complaint alleges EY "failed to meet its obligations to protect client information despite handling highly sensitive financial data as part of its tax and professional services businesses," per CFO Dive's reporting of the filing. The lawsuit states: "Only E&Y was in the position to ensure that its systems and protocols were sufficient to protect the PII and financial and tax information that Plaintiff and Class Members had entrusted to it."
These are allegations in a civil complaint, not findings by a court or regulator. No court has ruled EY was negligent. EY did not immediately respond to CFO Dive's request for comment on the suit.
The total number of affected clients isn't public. The lawsuit estimates it could run into the tens or hundreds of thousands given EY's global footprint of more than 400,000 employees across 150-plus countries, according to TechRadar. That is the plaintiff's estimate, not a confirmed figure from EY.
What EY Is Offering
EY is providing 24 months of free identity monitoring and restoration services through Experian to individuals it has notified, according to multiple outlets including ZDNET and TechRadar. Two years of monitoring is a standard corporate response to breaches like this, though it does little for anyone whose Social Security number is used for fraud in year three or beyond.
Clients who received a notification letter from EY should check what specific data points the letter lists as compromised. Anyone with a relationship to EY's tax practice who has not received a letter should not assume they're unaffected. EY has not disclosed the total scope, and it's unclear whether every impacted client has been notified yet.
The unresolved question is straightforward: how many people, exactly, and what specific data. EY hasn't said. Until it does, or until the class action forces disclosure through discovery, clients are left watching their bank statements and credit reports on their own.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.