Ernst & Young (EY) is notifying clients that personal and financial information used in tax filings was downloaded from a third-party IT service management (ITSM) / help-desk platform. Attackers had access March 28–April 12, 2026; EY detected anomalous activity on April 23. Texas became one of four states with AG filings when the firm reported on July 17, 2026 (873 Texans).
This is not a duplicate of our July 17 OAG week table, where EY is a single row, or the CPA firms listicle. This post focuses on ticket-attachment risk and the multi-state notice.

Snapshot
| Field | Detail |
|---|---|
| Firm | Ernst & Young LLP (ey.com) |
| System | Third-party ITSM / support ticket platform for tax-support IT |
| Access window | Mar 28 – Apr 12, 2026 |
| Detected | Apr 23, 2026 |
| Texas AG | Jul 17, 2026 — 873 Texans |
| Other states | California, Massachusetts, Vermont (and related notices) |
| Vendor named? | Not disclosed |
| Ransomware claim? | None reported as of mid-July coverage |
| Offer | 24 months identity monitoring (Experian; enroll by ~Oct 31, 2026 per notices) |
What may have been in the tickets
Support tickets can carry attachments. EY’s state filings describe personal and financial data in or used to prepare tax filings — including names, addresses, SSNs, account numbers, credit/debit data, and related filing contents. EY says it is not aware of misuse and has no indication specific individuals were targeted.
Why every Texas firm should care
Help-desk platforms are often monitored less than the ERP or tax engine — yet they accumulate the same PII. Inventory every ITSM tool that accepts attachments; prefer vaulted links with expiry over uploading W-2s and returns to tickets.
Independent cybersecurity audits
Audited July 25, 2026. 100% is the ideal — ey.com leads this story’s set but still falls short.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Ernst & Young | ey.com | 84% | 90% | 45% | 87% | −16 |
| BleepingComputer | bleepingcomputer.com | 63% | 75% | 15% | 40% | −37 |
How to read this table: 84% on ey.com (−16 from ideal) is strong public identity — it does not mean a vendor ITSM was monitored like core tax systems. Spoofed “EY tax security” email remains a post-notice risk.
Audit links: ey.com · bleepingcomputer.com
Website stack note
Passive website-tech probe on July 25, 2026 for ey.com: no notable public CMS / PHP / short-horizon TLS flags. That does not identify the third-party platform or access path. Point-in-time only.
What affected clients should do
- Enroll in the Experian offer in the letter by the stated deadline.
- Treat cold “EY breach portal” messages as phishing.
- Ask your tax advisor which support tools still allow PII attachments — and change that process.
Related
Run a free audit at audit.emailmenow.com or contact EmailMeNow for third-party ITSM reviews aimed at the 100% ideal.
Sources: BleepingComputer — EY support platform · Tech Times — EY four-state notices · SecurityWeek — EY personal/financial data · Texas OAG breach portal