News & Insights

EY Data Breach Exposes Personal and Financial Information

What happened?

In a recent notice letter sent to clients, Ernst & Young (EY) disclosed a data breach involving a third-party service management platform that supports its tax-related client work. The letter notified clients that EY identified anomalous activity within the platform on April 23, 2026, and immediately initiated its incident response procedure to determine the nature and scope of the incident.

EY clients affected by this breach have received the full notice letter from EY. Further, EY stated that its systems have been secured, federal law enforcement was notified, and that unauthorized access has been removed.

EY has offered affected clients complimentary access to credit and identity monitoring services to help protect their identities and has shared the steps clients need to take to activate the services in its official notice letter.

What does this mean for me?

This incident reinforces the importance of being aware of the third parties that maintain Firm data, what that data includes, and of conducting routine vendor due diligence on those firms. Under Amended Regulation S-P, Firms must conduct due diligence on service providers to ensure adequate safeguards are in place and provide notice no later than 72 hours after becoming aware of a breach in security resulting in unauthorized access to a customer information system maintained by the service provider.

If you have any questions or need assistance conducting vendor due diligence, please let us know. We have a full team dedicated to supporting clients with every facet of Amended Regulation S-P.