Share with your CISO
An unauthorized third party accessed EY’s external IT support ticket platform between March 26 and April 12, downloading documents containing client tax information before EY detected the anomalous activity on April 23. EY filed a breach notification with California on July 15, confirming that “a number of EY clients” were affected and that certain financial information used to prepare tax filings was exposed. The firm says systems are now secure, but the scope beyond California remains undisclosed.
What this means for your business
If your organization uses a Big Four firm for tax services, this breach isn’t EY’s problem alone. The exposed data sits in your tax filings, meaning your financials, entity structures, and transfer pricing details may be in the hands of an unknown third party. The companies most exposed are those whose IT support tickets contained sensitive financial attachments, a surprisingly common practice when finance and IT teams coordinate around tax software issues without treating those tickets as regulated data stores.
The attack surface here is the peripheral system problem, the recurring failure mode where a firm’s core environment is hardened but the supporting infrastructure around it, ticketing platforms, collaboration tools, file-sharing integrations, gets classified as “IT operations” rather than “sensitive data processing” and receives proportionally weaker controls. EY is not unique in this vulnerability. Any enterprise that manages client or customer data through third-party service-desk platforms, and nearly every large organization does, carries a version of this same exposure. The question worth asking internally is whether your own IT support ticket environment would pass a data-classification audit.
The three-week gap between initial unauthorized access and detection is the number that matters most here, not the breach itself. Detection lag is where breaches become catastrophic, because exfiltration is typically complete long before containment begins. If your security operations center’s mean time to detect on peripheral systems is measured in weeks rather than hours, the EY timeline is a leading indicator of what your own incident report could look like. I’d revise that concern if EY discloses that the ticketing platform sat genuinely outside their telemetry perimeter, but the notification language suggests otherwise.
Based on reporting from EY reports data breach on IT support ticket platform: Trial Balance, originally published 2026-07-20 09:56:00.

