EY breach: when support tickets hold client tax files
Attackers took tax documents attached to tickets on a platform EY's tax teams used. What happened, and what to check in your own ticket systems and vendors.
By Yaali. October 8, 2026, 6 min read, Threat intel, Resilience.
Ernst & Young LLP (EY) is still notifying people whose tax documents were taken from a third-party IT service management (ITSM) platform, the ticketing system its IT staff use to support EY teams doing tax work for clients. EY says an unauthorized party had access between March 28 and April 12, 2026 (one CFO.com report gives March 26 as the start) and downloaded documents that had been attached to support tickets. EY spotted the activity on April 23 and has not named the platform, the vendor or how many people are affected.
The story widened at the end of September. According to the Financial Times, as relayed by several security outlets, new letters told clients of Goldman Sachs' wealth management business and of hedge fund Man Group that their data was in the stolen files: names, addresses, tax identification numbers, email addresses and financial details. Both firms say their own systems were not touched. If your organisation sends documents to an accountant, auditor or outsourced service desk, this is the pattern to check for.

How it works
An ITSM platform is where staff raise a ticket when something breaks: a report will not run, a file will not import, a workbook gives the wrong total. To reproduce the problem, the support engineer needs the input, so people attach it. In a tax practice the input is a client's tax workpapers. After a few years of reasonable requests like this, the ticket system holds a large, searchable archive of client financial records that nobody classified as a data store.
These archives tend to sit outside the controls applied to the main document systems. Tickets are kept for audit and reporting, so attachments rarely expire. Access is broad, because support staff, contractors and the vendor's own engineers all need to read tickets. Downloads are rarely logged in a way anyone reviews. EY's notice confirms the starting point: support tickets "may include documents containing client tax information," and the attacker downloaded multiple documents over about two weeks before anyone noticed.
How the attacker got in is uncertain. The Financial Times reports that EY attributed the incident to a vulnerability in Checkmarx software, but no CVE, product version or exploitation method has been published, and neither EY nor Checkmarx has explained the link. Separately, Checkmarx disclosed in March that the TeamPCP group had tampered with its checkmarx/ast-github-action and checkmarx/kics-github-action GitHub Actions on March 23, using tokens stolen in the Trivy compromise four days earlier. No source has connected that incident to EY, and we are not drawing a connection here.
What attackers did, and what is claimed
EY's confirmed account is short: access to one third-party platform, documents downloaded, no evidence of misuse so far, systems secured, federal law enforcement told. Notice letters are dated July 13, and EY filed with the California Attorney General on July 15. That filing came 83 days after detection, and a second round of letters followed in late September.
On July 27 the ShinyHunters extortion group added EY to its leak site with a July 31 deadline. It told BleepingComputer it had obtained EY credentials through a supply-chain attack on a third party it would not name, and used them to get into EY's Jira, GitHub and Azure environments. EY has not confirmed that ShinyHunters was involved, and nobody has independently verified the wider access claim.
Goldman Sachs told its clients on September 24, the FT reports, that EY had brought in an independent security firm to confirm the platform was secure, and that Goldman's Technology Risk team wants evidence and outside validation of EY's fixes.
What to do
If you received an EY letter, enroll in the 24 months of Experian IdentityWorks monitoring it offers before October 31, 2026. Because tax identification numbers were exposed, US recipients should also request an IRS Identity Protection PIN through their IRS online account, which stops anyone else filing a return under that number. Place credit freezes with the three bureaus as well.
If EY or another adviser handles your company's tax work, ask them in writing which of your documents sat in the affected platform, whether they include employee or investor data, and what the independent firm checked. Your own breach-notification duties to staff or investors may depend on the answer.
Then look at your own ticket systems, because the same pattern is likely to exist there:
- Run an attachment inventory. In ServiceNow, the
sys_attachmenttable lists every file with itstable_nameand size; in Jira Data Center, thefileattachmentdatabase table does the same, linked to issues byissueid. Sort by file type and look for spreadsheets, PDFs and archives on old, closed tickets. - Set a retention rule that deletes or archives attachments a fixed time after a ticket closes. The ticket text can stay for reporting.
- Give staff a secure place to share files during support, such as a document link with expiry and access logging, and add guidance to the ticket form telling people not to attach client or HR data.
- Turn on and forward the platform's audit log for attachment downloads and API exports, and alert on one account pulling many attachments in a short window. The EY attacker kept downloading documents for about two weeks.
- Review who can read attachments, including vendor support accounts and API integration users. Remove standing access for anyone who only needs it during an escalation.

What to ask your own vendors
Vendor security questionnaires usually cover the main product and skip the support channel. Add these questions for any provider that receives your files: where do files sent in support cases end up, how long are they kept, who at the vendor and its subcontractors can read them, which third-party ticketing or developer tools sit in that path, and how soon would you be told if one of those tools were breached. Ask for the answer to the last one in the contract, in days.
When a provider does report an incident, follow Goldman's lead and ask for evidence rather than a statement: the scope of the independent review, the list of affected documents tied to your account, and confirmation of which credentials and tokens were rotated.
Mapping where your data actually goes, including vendors' support tools, is part of our compliance and audit readiness work, and we review ticketing and collaboration platforms for exposed files in safeguarding and hardening engagements. If you want help checking your own ticket attachments or writing vendor questions, open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: CyberInsider, Security Affairs, CFO.com, BleepingComputer, teiss, Cyber Security News, GBHackers, The Hacker News, SOCRadar.
Read next
- Oracle Health Cerner breach count jumps to 20 million
- Linux backdoors pose as mail security tools in Korea, Taiwan
- Denmark CPR breach: one firm's lookup access, 8.8M people
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.