Just as EY was moving on from the 2023 MOVEit data breach in which more than 30,000 Bank of America customers may have had their personal information compromised, a fresh breach has popped up. It sounds like it could be another financial services customer of EY’s was involved, as they said the following in the firm’s notice to potentially affected individuals:
EY provides professional tax services to a wide range of financial institutions globally. In the course of providing these tax services, EY received certain personal financial information relating to your investment holdings with [EY CUSTOMER].
You may have noticed that [EY CUSTOMER] is a placeholder. As of now, we don’t know which EY client was involved.
EY began informing affected individuals and relevant state authorities on July 13. In their notice filed with the California Attorney General, which we’ve embedded in its entirety below, they say:
EY uses a third-party information technology service management platform to help EY information technology provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.
They then launched an incident response and brought in an independent cybersecurity firm.
We don’t know which third-party IT service was involved as they haven’t said. Nor have they named any hacker group involved. Clearly this article is begging for an update, hopefully soon.
The personal information affected includes “certain financial information contained in or used to prepare tax filings.” The firm says they are “not aware of any misuse or further exposure of your personal information as a result of this incident.” As is standard protocol in a data breach like this, they are offering free access to two Experian products, Identity works and Identity Restoration.
There is already a potential class action lawsuit in the works.

