Back to news
Cybersecurity Alert
July 25, 2026 by EmailMeNow IT Consulting

EY Tax Data Stolen Through Third-Party Help-Desk Platform — Texas Among Four States Notified

Ernst & Young notified clients after attackers accessed a third-party ITSM help-desk platform Mar 28–Apr 12, 2026 and downloaded tax documents. Texas AG filing July 17 lists 873 Texans. Audits (100% ideal): ey.com 84% — still −16 from ideal.

Source: BleepingComputer · Tech Times · Texas OAG

NewsData BreachTaxThird-Party RiskTexasCybersecurity
Help-desk support tickets with tax document attachments being accessed

Ernst & Young (EY) is notifying clients that personal and financial information used in tax filings was downloaded from a third-party IT service management (ITSM) / help-desk platform. Attackers had access March 28–April 12, 2026; EY detected anomalous activity on April 23. Texas became one of four states with AG filings when the firm reported on July 17, 2026 (873 Texans).

This is not a duplicate of our July 17 OAG week table, where EY is a single row, or the CPA firms listicle. This post focuses on ticket-attachment risk and the multi-state notice.

Help-desk support tickets with tax document attachments being accessed

Snapshot

FieldDetail
FirmErnst & Young LLP (ey.com)
SystemThird-party ITSM / support ticket platform for tax-support IT
Access windowMar 28 – Apr 12, 2026
DetectedApr 23, 2026
Texas AGJul 17, 2026873 Texans
Other statesCalifornia, Massachusetts, Vermont (and related notices)
Vendor named?Not disclosed
Ransomware claim?None reported as of mid-July coverage
Offer24 months identity monitoring (Experian; enroll by ~Oct 31, 2026 per notices)

What may have been in the tickets

Support tickets can carry attachments. EY’s state filings describe personal and financial data in or used to prepare tax filings — including names, addresses, SSNs, account numbers, credit/debit data, and related filing contents. EY says it is not aware of misuse and has no indication specific individuals were targeted.

Why every Texas firm should care

Help-desk platforms are often monitored less than the ERP or tax engine — yet they accumulate the same PII. Inventory every ITSM tool that accepts attachments; prefer vaulted links with expiry over uploading W-2s and returns to tickets.

Independent cybersecurity audits

Audited July 25, 2026. 100% is the idealey.com leads this story’s set but still falls short.

OrganizationDomainOverallIdentityTransportWebsitevs 100% ideal
Ernst & Youngey.com84%90%45%87%−16
BleepingComputerbleepingcomputer.com63%75%15%40%−37

How to read this table: 84% on ey.com (−16 from ideal) is strong public identity — it does not mean a vendor ITSM was monitored like core tax systems. Spoofed “EY tax security” email remains a post-notice risk.

Audit links: ey.com · bleepingcomputer.com

Website stack note

Passive website-tech probe on July 25, 2026 for ey.com: no notable public CMS / PHP / short-horizon TLS flags. That does not identify the third-party platform or access path. Point-in-time only.

What affected clients should do

  1. Enroll in the Experian offer in the letter by the stated deadline.
  2. Treat cold “EY breach portal” messages as phishing.
  3. Ask your tax advisor which support tools still allow PII attachments — and change that process.

Run a free audit at audit.emailmenow.com or contact EmailMeNow for third-party ITSM reviews aimed at the 100% ideal.


Sources: BleepingComputer — EY support platform · Tech Times — EY four-state notices · SecurityWeek — EY personal/financial data · Texas OAG breach portal