Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next
Follow ZDNET: Add us as a preferred source on Google.

Follow ZDNET: Add us as a preferred source on Google.
Ernst & Young has disclosed a data breach that resulted in the theft of clients' personal information. From March 28 to April 12, attackers had access to a third-party support ticket system containing customer information related to their tax affairs.
Also: Is that QR code a trap? How to spot quishing scams before it's too late
A data breach notice was filed with the California Attorney General's office on July 15, as well as other states , including Massachusetts and Vermont. Ernst & Young has since begun notifying customers of the security incident.
According to the organization's notice to clients [PDF] , the data breach was caused by an intrusion into a third-party IT platform that Ernst & Young uses to handle tax-related work for clients. The support system allows Ernst & Young teams to submit support tickets, which may contain sensitive customer information.
Also: I connected ChatGPT to my bank, and it's my go-to finance app now - here's how (and why)
For roughly two weeks in March and April, the cybercriminal responsible for the breach was able to download records "pertaining to a number of EY clients," according to the notice.
Ernst & Young detected suspicious activity on the platform on April 23 and hired a cybersecurity firm to investigate the incident. The support ticket system has now been secured, although no further details -- on the compromise, any use of malware, or the responsible party -- have been disclosed.
Ernst & Young says in the notification letter that "certain financial information contained in or used to prepare tax filings" and the sample notice includes a placeholder for customers' specific data points.
The Big Four accounting firm has not disclosed exactly what records were leaked. It is possible that personal, sensitive data necessary for tax filing could be included, such as names, addresses, Social Security numbers, financial account information, and other records, but until Ernst & Young formally discloses this information, we can't be sure.
Also: The 10-step phone security tune-up you should run every year - and why
EY added in the notice that the organization is "not aware of any misuse or further exposure of [your] personal information as a result of this incident," and also says there is no "indication [your] personal information was specifically targeted."
Source: ZDNet