Ernst & Young LLP Data Breach Investigation

Chimicles Schwartz Kriner & Donaldson-Smith is investigating potential class action claims against Ernst & Young LLP (“EY”) on behalf of financial institution customers, investors, and other individuals whose personal and financial information may have been compromised in a recently disclosed data security incident involving a third-party IT support platform used by EY’s tax services personnel.

What Happened?

On April 23, 2026, EY, one of the “Big Four” global professional services firms, identified anomalous activity on a third-party information technology service management platform used by its IT personnel to support EY teams performing tax-related work for clients. EY’s Information Security team initiated its incident response procedure, engaged an independent cybersecurity firm, and notified federal law enforcement.

Based on EY’s investigation, an unauthorized third party accessed the platform between March 28, 2026 and April 12, 2026 and downloaded documents pertaining to a number of EY clients. Support tickets submitted through the platform may have included document attachments containing client tax information.

EY began issuing individual notice letters dated July 13, 2026 via U.S. Mail and email, and reported the incident to the California and Massachusetts Attorneys General on July 15, 2026, to the Vermont Attorney General on July 16, 2026, and to the Texas Attorney General on July 17, 2026. Public state filings reflect at least 873 Texas residents, 480 Massachusetts residents, and 13 Vermont residents affected, with the California filing (which is required only for breaches affecting more than 500 California residents) suggesting a substantially larger overall population. EY has not publicly disclosed the total number of affected individuals, the identity of the compromised third-party vendor, or whether the incident extends beyond its U.S. client base.

Who May Be Affected?

EY provides professional tax services to a wide range of financial institutions globally. Many affected individuals may not have had a direct relationship with EY; rather, their personal information was provided to EY by financial institutions in connection with investment-related tax work. You may have been affected if you:

  • Received a data breach notification letter from Ernst & Young LLP dated on or around July 13, 2026
  • Hold investment accounts with a financial institution that uses EY for tax preparation or related professional tax services
  • Provided tax-related personal information to a financial institution that engaged EY in connection with investment holdings

What Information May Have Been Compromised?

According to state regulatory filings, the affected files may have contained an individual’s name together with one or more of the following categories of personal and financial information:

  • Contact information (address, email, telephone number)
  • Date of birth
  • Social Security number
  • Driver’s license number
  • Credit or debit card number
  • Financial account code
  • Financial account information related to tax filings

Why Is This Important?

The reported combination of Social Security numbers, driver’s license numbers, dates of birth, and financial account and card data is precisely the bundle of identifiers most commonly exploited for identity theft, synthetic identity fraud, fraudulent loan and credit applications, tax-refund fraud, and targeted phishing or social engineering schemes. Because the documents at issue were tax preparation materials, they may also expose income, employer, and investment activity information that heightens the risk of tailored fraud and impersonation.

What Should You Do?

If you received a data breach notification letter from Ernst & Young LLP, or if you hold investment accounts with a financial institution that engaged EY for tax services, you may have been affected by this incident. Please contact our data breach attorneys by completing the form below to learn more about your potential legal rights and our ongoing investigation.

Ernst & Young Data Breach (#942)

(*) Indicates required field: When communicating with us through this site or otherwise in connection with a matter for which we do not already represent you, your communication may not be treated as privileged or confidential, and does not create an attorney-client relationship between you and our Firm.