Ernst & Young 2026 Data Breach Analysis: Third-Party IT Support Platform Compromise Exposes Sensitive Client Information

Ernst & Young 2026 Data Breach Analysis: Third-Party IT Support Platform Compromise Exposes Sensitive Client Information

Executive Summary

Publication Date: July 15, 2026

In March and April 2026, Ernst & Young (EY), one of the world’s largest professional services firms, experienced a significant data breach through a compromise of a third-party IT support platform. This incident, first reported by the Financial Times on July 15, 2026, exposed highly sensitive client data, including tax documents and personally identifiable information (PII) for major clients such as Goldman Sachs’ wealth management division and Man Group. The breach was orchestrated by the ShinyHunters extortion group, who claimed responsibility and threatened to leak the stolen data. The attack highlights the acute risks posed by third-party platforms in the modern supply chain and underscores the necessity for robust third-party risk management (TPRM) and data governance practices.

Technical Information

The Ernst & Young breach is a textbook example of a supply-chain attack leveraging a trusted third-party platform to bypass traditional perimeter defenses. The attack vector was an unauthorized intrusion into a third-party IT service management (ITSM) or support-ticket platform used by EY to facilitate client support, particularly for tax-related services. The specific vendor has not been publicly disclosed, but industry speculation has centered on leading ITSM providers such as ServiceNow and Atlassian, though neither has been confirmed as the affected party.

Attack Timeline and Discovery

The initial unauthorized access began on March 28, 2026, and persisted until April 12, 2026. During this window, the attackers exfiltrated a trove of sensitive documents. EY detected anomalous activity on April 23, 2026, triggering an internal incident response. Public notification and regulatory filings commenced in July 2026, with breach notices filed in California, Texas, Massachusetts, and Vermont, affecting at least 1,866 individuals, though the true scope is likely broader given EY’s global client base.

Attack Vector and Exploitation

The attackers exploited the trusted relationship between EY and its ITSM vendor, leveraging either compromised credentials or a vulnerability in the support platform to gain persistent access. The ShinyHunters group, known for high-profile supply-chain and credential theft attacks, claimed responsibility, alleging they obtained access to Jira, GitHub, and Azure environments as well. However, EY has not confirmed these claims, and no independently verified data dump has been observed as of July 31, 2026.

The breach primarily involved the exfiltration of documents submitted as attachments to support tickets. These included tax filings, names, addresses, Social Security numbers, account numbers, credit/debit card numbers, and other sensitive tax-related information. The attackers’ dwell time—approximately 11 days—allowed for the systematic harvesting of data before detection.

Data Handling and Shadow Archives

A critical technical insight from this incident is the role of ITSM platforms as “shadow archives” for regulated data. Support-ticket systems, often outside the direct control of core IT security teams, can accumulate vast quantities of sensitive attachments. These platforms may lack the rigorous data retention, access control, and monitoring policies applied to primary systems of record, making them attractive targets for adversaries.

MITRE ATT&CK Mapping

The tactics and techniques observed in this breach align with the following MITRE ATT&CK framework entries:

  • T1199: Trusted Relationship – The attackers exploited a trusted third-party relationship to gain access to sensitive data.
  • T1213: Data from Information Repositories – The attackers exfiltrated documents and data from the ITSM platform.

Threat Actor Profile

ShinyHunters is a prolific cybercriminal group specializing in supply-chain and third-party breaches, credential theft, and extortion. While not classified as a nation-state advanced persistent threat (APT), their operations are sophisticated and opportunistic, often targeting organizations with complex vendor ecosystems.

Absence of Technical Indicators

No Common Vulnerabilities and Exposures (CVE) identifiers have been associated with this incident, and no public indicators of compromise (IOCs) such as hashes, IP addresses, or domains have been released. This lack of technical detail complicates defensive efforts and underscores the importance of proactive vendor and data governance.

Regulatory and Notification Actions

EY initiated notification letters to affected individuals beginning July 13, 2026, and filed breach notices with state regulators in California, Texas, Massachusetts, and Vermont. The breach notification process included offers of identity monitoring services, with enrollment windows set to expire by October 31, 2026.

Recommendations for Risk Mitigation

In light of this incident, organizations should undertake a comprehensive review of their ITSM and support-ticket platforms. Key recommendations include:

Conducting a full inventory and audit of all ITSM/helpdesk platforms capable of receiving attachments, with a focus on identifying repositories containing regulated data.

Implementing strict data handling policies to restrict or prohibit the inclusion of tax documents, PII, and payment card data in support tickets. Where such data transfer is unavoidable, deploying data loss prevention (DLP) controls to ensure sensitive information remains within systems of record.

Enforcing short data retention periods and purging sensitive attachments upon ticket closure to minimize the risk of data accumulation in shadow archives.

Applying robust access controls, including multi-factor authentication (MFA) and least-privilege principles, to all ITSM platforms. Limiting bulk download and export capabilities to reduce the risk of mass data exfiltration.

Establishing continuous monitoring for anomalous downloads and access patterns, with automated alerting for suspicious activity.

Requiring contractual transparency from vendors regarding the use of subprocessors, breach notification service-level agreements (SLAs), and adherence to SOC 2 or equivalent compliance standards.

Conducting regular tabletop exercises simulating vendor-ITSM compromise scenarios, including the assessment of fourth-party risk pathways.

Ensuring that breach notification and identity monitoring enrollment windows are clearly communicated and time-bounded for affected individuals.

Broader Implications

This breach serves as a stark reminder that third-party platforms can become critical points of failure in the cybersecurity posture of even the most sophisticated organizations. The compromise of a trusted support platform enabled attackers to bypass perimeter defenses and access highly regulated client information. The absence of technical IOCs and CVEs further complicates detection and response, emphasizing the need for holistic TPRM and continuous monitoring.

References

Financial Times: "Ernst & Young data breach exposes Goldman Sachs and Man Group client information" (July 15, 2026) – https://www.ft.com/content/2ad1ff25-f08e-4e78-83c9-90e7ea3844ee

Rescana Analysis: "Ernst & Young Data Breach Analysis: Third-Party IT Support Platform Compromise Exposes Client Tax and Financial Information" – https://www.rescana.com/post/ernst-young-data-breach-analysis-third-party-it-support-platform-compromise-exposes-client-tax-and-financial-information

BleepingComputer: "Ernst and Young discloses data breach after support system hack" – https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/

BleepingComputer: "Ernst and Young data breach claimed by ShinyHunters extortion gang" – https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/

SecurityWeek: "Ernst & Young Data Breach Affects Personal, Financial Information" – https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-information/

SecurityAffairs: "Ernst & Young (EY) investigates data breach involving third-party support tickets" – https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html

California DOJ Sample Notice: https://oag.ca.gov/ecrime/databreach/reports/sb24-626542

ComplexDiscovery: "ShinyHunters’ July 31 deadline for EY arrives after third-party tax data breach" – https://complexdiscovery.com/shinyhunters-july-31-deadline-for-ey-arrives-after-third-party-tax-data-breach/

Rescana is here for you

At Rescana, we understand that the modern threat landscape is defined by complex supply chains and interconnected platforms. Our advanced TPRM platform empowers organizations to continuously assess, monitor, and mitigate third-party risks, ensuring that your data and reputation remain protected. We are committed to providing actionable intelligence and expert guidance to help you navigate the evolving cybersecurity environment. If you have any questions or require further assistance, our team is always available at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.