The weakest link: EY’s data breach and the expanding attack surface of Big Four AI
How a third-party support system exposed EY US client tax data — and what it reveals about the expanding attack surface surrounding Big Four AI
Key Takeaways
The attacker who obtained client tax documents held by Ernst & Young LLP, EY’s US member firm, earlier this year did not enter through one of the firm’s flagship tax or artificial-intelligence platforms.
According to EY’s notification letter, an unauthorised party instead gained access to a third-party IT service-management platform used by EY technology personnel to support teams performing tax-related work for clients.
Support tickets submitted through the platform often contained documents holding client tax information. EY’s investigation found that, between 28 March and 12 April 2026, an unauthorised third party accessed the platform and downloaded documents relating to what EY described as “a number of EY clients”.
EY identified anomalous activity on 23 April, 11 days after the last known unauthorised access. The firm says it activated its incident-response procedures, worked with an independent cybersecurity firm, stopped the access, secured its systems and notified federal law-enforcement authorities.
Notification letters dated 13 July said the affected material included personal information and financial information contained in, or used to prepare, tax filings. The sample notice was addressed not directly to an EY client, but to someone whose information EY had received in connection with their investment holdings with an EY client.
The breach therefore has several layers. The affected individuals may include customers, investors or employees of organisations that engaged EY. Some may not previously have known that EY possessed or processed their information.
EY said it was not aware of misuse or further exposure and had no indication that particular individuals had been specifically targeted. It offered recipients 24 months of Experian identity-monitoring and restoration services.
The public notice does not identify the third-party platform, explain how access was obtained or disclose the total number of affected clients and individuals. Nor does it say when each client was first informed.
One question is particularly difficult to avoid: why were sensitive tax documents present in an IT support-ticket environment in the first place?
The EY US 2026 data breach timeline
28 March 2026: The period of unauthorised access begins.
28 March–12 April: An unauthorised party accesses the third-party support platform and downloads documents relating to a number of EY clients.
12 April: The last known date of unauthorised access.
23 April: EY detects anomalous activity and begins its investigation, containment and remediation work.
After 23 April: EY engages independent cybersecurity specialists, stops the unauthorised access, secures its systems and notifies federal law enforcement. The dates of those individual steps have not been disclosed.
13 July: EY dates its notification letters to affected individuals.
15 July: Ernst & Young LLP reports the breach to the California Attorney General. California requires a sample notice to be provided when notices are sent to more than 500 state residents. The filing therefore confirms that notices were sent to at least 501 California residents, although neither the exact state total nor the overall number of affected individuals has been disclosed.
17 July: The incident receives wider public attention through specialist cybersecurity reporting.
A possibly related client disclosure
On 15 June, Easterly Government Properties disclosed a third-party security incident at its professional tax-services provider, EY. Easterly said the acquired information included names, mailing addresses, Social Security numbers, taxable income and tax-related footnote information.
Public documents do not confirm that Easterly was affected by the same support-platform breach. While the timing and nature of the data make a link possible, the possibility currently remains unverified.
This was not EY’s first warning
In 2023, EY was among the many organisations affected by a vulnerability in Progress Software’s MOVEit Transfer product.
EY US used the third-party application to transfer data files. Its notification said that compromised files could contain names, addresses, financial-account information, payment-card details, Social Security numbers and other government identification data.
Some of the information belonged to Bank of America customers whose data EY received while providing consulting, advisory and tax services to the bank. Bank of America said its own systems and servers had not been affected; the exposure occurred within the supplier’s software.
In 2025, researchers at Neo Security discovered a four-terabyte unencrypted SQL Server backup associated with EY that was publicly accessible on Microsoft Azure. EY said the issue was confined to an entity acquired by EY Italy, was unconnected to EY’s global systems and had affected no client information, personal data or confidential EY data.
Neo Security examined only the first portion of the file — enough to confirm it was an unencrypted database backup — and the duration of the exposure remains unknown. The public record therefore does not establish whether anyone else found or downloaded the file before it was secured.
EY is far from alone.
PwC Australia was also affected by MOVEit. Its 2023 transparency report said PwC’s own IT network was not compromised, but that some historic engagement files had been accessed through the third-party application. PwC ceased using the platform, investigated the incident and contacted affected clients after finding that some historic engagement files had been accessed.
In 2017, Deloitte acknowledged unauthorised access to its email platform. The firm said the data of a small number of clients had been affected. Reporting linked the intrusion to a privileged administrator account.
In 2019, KPMG Mexico acknowledged that a small group of staff had created an unauthorised and inadequately secured Azure environment containing confidential payroll and tax information associated with employees of 41 clients.
These incidents involved different systems, circumstances and levels of confirmed harm. But together they illustrate how client information can be placed at risk through a supplier, a software vulnerability, a cloud configuration, a privileged credential, an acquired business or an unauthorised local environment.
The central platform is not the whole security perimeter.
Not an AI breach—but a warning about AI architecture
This breach did not involve EY’s Global Tax Platform, its EY.ai Agentic Platform or any other EY artificial-intelligence system. However, the fact remains that as EY connects client information to more data platforms, applications, suppliers and AI agents, its effective security boundary expands with them.
Protecting the central platform is essential, but it is not sufficient if the same information can be reached through another connected system or operational process.
The real question is whether the much larger ecosystem being constructed around EY’s AI infrastructure can prevent sensitive information from being exposed through a less protected route.
EY is building an AI operating system for tax
EY’s public materials show the scale and direction of its tax-technology strategy.
The EY Global Tax Platform uses Microsoft Azure infrastructure to store client data in a data-lake repository. EY says the platform supports data gathering, integration, classification, analysis and reuse across the end-to-end delivery of tax services.
It also integrates external tax engines on what EY describes as a “plug-and-play” basis and stores all relevant data for those services within one technology platform.
This means that EY’s tax model is moving towards centralised, cloud-based environments designed to bring together data that may previously have been dispersed across jurisdictions, source systems and individual documents.
The scale increases considerably when artificial intelligence is added.
In March 2025, EY announced that the initial deployment of its EY.ai Agentic Platform would integrate 150 AI agents supporting 80,000 professionals. The firm said the agents would contribute to more than three million tax-compliance deliverables and reshape 30 million tax processes annually, including data collection, document analysis, review and compliance work.
The platform, created with NVIDIA, was designed to operate across client clouds, on-premises environments, edge systems and NVIDIA’s cloud-provider ecosystem. EY’s agentic framework was also designed to operate across third-party agent platforms.
Later in 2025, EY launched its Tax Agent Factory, which it describes as a global accelerator enabling EY professionals and clients to design, build, train, deploy and manage AI agents at scale. The capability draws on what EY calls its “multi-alliance ecosystem” of technology providers.
EY and IBM have separately developed AI tax solutions using IBM watsonx. EY says the technology offers access to an enriched tax data lake and can analyse millions of rows, automate workflows and detect historical errors.
These are not simply writing assistants added to the edge of a tax practice.
They are components of an increasingly connected operating architecture designed to collect data, reconcile it, interpret it, identify exceptions, coordinate workflows and perform parts of the work itself.
That architecture offers obvious benefits. It can reduce repetitive tasks, improve consistency and help professionals detect patterns or errors that would be difficult to identify manually.
It also alters the consequences of a security failure.
From stored data to usable intelligence
The Big Four have always possessed enormous quantities of confidential information.
What changes in the AI era is not only the volume of that information. It is the ease with which the information can be located, connected, interpreted and acted upon.
A conventional repository may contain millions of documents. Unless someone knows what exists and where it is located, much of that information remains difficult to exploit at scale.
A connected AI environment is designed to overcome precisely that limitation.
Depending on its configuration and permissions, it may search structured databases and unstructured documents, identify links between individuals and companies, extract significant facts, compare data from several systems and turn fragmented material into a coherent answer.
Within a tax environment, that information might include tax returns, working papers, payroll records, accounting ledgers, ownership structures, investment holdings, transaction data, internal correspondence and regulatory submissions.
The security question consequently changes.
It is no longer simply:
How many files could an attacker download?
It becomes:
What could the connected system discover, combine and do once access had been obtained?
A breach of disconnected documents may expose individual records.
Access to a sufficiently connected AI environment could potentially help an attacker identify the most valuable information within a much larger data estate—and understand its significance far more quickly.
The risk is therefore not merely that more data could be exposed. It is that the systems developed to make the information useful could also make it easier to exploit after a weakness is found.
Multiple doors into the same architecture
An AI platform does not operate alone.
It may depend on cloud infrastructure, model providers, data lakes, identity systems, software libraries, document repositories, tax engines, support services and numerous application-programming interfaces.
It may connect to client ERP platforms, payroll systems, financial ledgers, email, document-management environments and regulatory databases.
Every connection adds functionality. Every connection must also be governed and protected.
A weakness could arise through:
a cloud or software supplier;
a stolen administrator, developer or support credential;
an inadequately secured API or data connector;
a misconfigured backup or storage environment;
a malicious document processed by an AI agent;
an agent granted broader permissions than its task requires.
Some of these risks are familiar. Others arise from the way generative and agentic AI operates.
An apparently ordinary document can contain hidden instructions intended to manipulate an AI system. A compromised connector can allow lateral movement between environments. Poisoned information can corrupt a reusable workflow. An over-permissioned agent can retrieve data or perform actions beyond the purpose for which it was deployed.
Deloitte’s Tech Trends 2026 identifies input injection, unauthorised access, insecure APIs, supply-chain vulnerabilities, deployment misconfigurations and excessive agency among the risks surrounding AI systems.
These are not allegations concerning EY’s present platforms.
They are recognised risks inherent in connecting AI to sensitive information and giving it access to external tools and applications.
A global platform—and uneven control
The Big Four operate through networks of legally separate member firms, acquired businesses, offshore delivery centres, contractors, secondees and local technology suppliers. Their systems may vary in age, staffing, configuration and level of integration.
This raises a serious risk relating to uneven control across the network. A smaller office may depend more heavily on external IT support. An acquired company may retain inherited systems. A local team may develop a workaround outside the authorised environment. Permissions granted for one assignment may remain after a professional has moved elsewhere.
The KPMG Mexico incident reportedly involved an unauthorised local environment. EY said its 2025 Azure exposure was confined to an acquired entity outside its global cloud and technology systems.
Neither incident establishes that a peripheral environment provided access to the wider network. But they illustrate why global organisations must know what exists at their edges and ensure that systems outside the central architecture cannot become routes towards it. This is an inference from the incidents, rather than evidence that either firm’s wider network was compromised.
The vulnerability is not geography.
It is inconsistency.
The firms have already written the warning
None of this advice is unfamiliar to the Big Four.
All four firms publish reports telling clients to manage precisely these risks. Their own words map remarkably closely onto the vulnerabilities highlighted by EY’s latest incident.
EY: scrutinise suppliers and data sources
In AI and cybersecurity: The new frontier of business resilience, EY advises organisations:
“Require suppliers to disclose their security posture and patch vulnerabilities quickly.”
— Page 15.
On the same page, EY recommends verifying the provenance of models and data sources, isolating AI environments, enforcing least privilege, monitoring anomalies and maintaining procedures for rapidly shutting down systems that behave unexpectedly.
Deloitte: AI can expose sensitive information
Deloitte’s Tech Trends 2026 warns:
“AI tools can inadvertently expose sensitive data.”
— Page 54.
The report also identifies data poisoning, model inversion, excessive agency, insecure APIs and supply-chain vulnerabilities. Its recommended controls include cataloguing data sources, monitoring integrity and applying least-privilege access to training data and supporting services.
PwC: the weakest points may sit in the supply chain
PwC’s New world, new rules: Cybersecurity in an era of uncertainty — 2026 Global Digital Trust Insights observes:
“Legacy systems and supply chain exposures are among the weakest spots.”
— Page 7.
PwC says growing technological and ecosystem complexity is straining organisations’ ability to keep pace, particularly across third-party and supply-chain dependencies.
KPMG: third-party agents bring new risks
KPMG’s Cybersecurity considerations 2026: Building trust and enabling innovation in a dynamic world states:
“Some AI agents are sourced directly from third-party suppliers or embedded in products.”
— Page 16.
KPMG says this accessibility introduces new risks and recommends secure configuration, continuous testing and formal contractual accountability for third-party AI suppliers. The report also warns that AI agents are gaining greater privileges, accessing vast amounts of data and acting at speeds that existing security practices may struggle to match.
The irony does not need to be overstated. The Big Four routinely advise clients to know where their data travels, restrict access, scrutinise suppliers and monitor anomalous behaviour.
Their expanding AI infrastructures will test whether they apply those disciplines to themselves.
The attackers are scaling too
The firms are not the only organisations using AI to work faster.
In May, Google’s Threat Intelligence Group described a transition towards the industrial-scale use of generative models within hostile operations. It reported identifying a criminal threat actor using a zero-day exploit that Google believed had been developed with AI for a planned mass-exploitation campaign.
Google also described AI-assisted vulnerability research, exploit development, defence evasion and malware capable of interpreting system conditions and dynamically generating commands. It separately reported that adversaries had begun targeting AI software dependencies as a route into broader network environments.
The Big Four are therefore increasing the number and capabilities of the systems connected to client data at the same time that attackers are becoming better equipped to search those connections for weaknesses.
But the threat does not always begin outside the organisation.
The authorised person inside the system
Technology suppliers and external attackers are only part of the enlarged attack surface. Another risk sits within it: an employee, contractor or secondee who already has legitimate access.
Two EY employees on temporary assignment at Commonwealth Bank were reportedly dismissed after restricted information—including the banking details of Prime Minister Anthony Albanese and at least one EY partner—was allegedly accessed.
An Australian Federal Police statement reported by Reuters said two men had been charged in connection with alleged unauthorised access to restricted banking data. One was also charged over the alleged publication or distribution of personal information. The allegations have not been proven and remain before the courts.
The significance of the case for AI governance lies in the alleged route of access.
EY itself identifies the wider insider danger in Safeguarding advanced technology from insiders:
“Insider cooperation can be voluntary, driven by a diverse range of motivations.”
— Page 2.
The insider may act for personal gain, assist an outside party or take information to a future employer. An apparently legitimate account may also belong to an innocent employee whose credentials have been compromised.
In each case, the system initially sees an authorised identity.
What I saw in professional services
The insider risk is not merely theoretical. During my career in professional services, I encountered cases in which departing employees attempted to transfer client-related material outside the organisation using access they legitimately retained before leaving.
One attempt involved removable storage. Another involved documents being sent to an external email account. Internal monitoring detected the activity, and steps were taken to secure deletion.
AI could make the same underlying misconduct considerably more efficient.
A departing employee who once had to know which folders to search and which documents to copy could potentially use a connected system to locate material across multiple repositories, compare proposals, extract client information, identify valuable methodologies and summarise the results.
That is a hypothetical risk, not an allegation concerning any existing Big Four platform. But it demonstrates why conventional access rights may no longer be sufficient.
An organisation must ask not only which documents a user can open, but what its AI systems can retrieve, combine and assemble on that user’s behalf.
The Big Four’s own test
No organisation can guarantee that it will never experience a cyberattack or attempted insider breach.
Third-party technology is unavoidable. Modern professional-services firms cannot operate globally without cloud platforms, specialist software, technology alliances and outsourced infrastructure.
The issue is not that the Big Four use third parties. Nor is it that they are adopting AI.
The issue is whether the speed at which they are connecting data, systems and increasingly autonomous tools is being matched by improvements in data minimisation, client segregation, supplier oversight, identity management, monitoring and incident response.
EY’s latest breach shows that sensitive tax information can travel beyond a primary workflow and accumulate inside another part of the technology chain.
As the Big Four build AI systems capable of reaching across global data lakes, client applications and third-party ecosystems, they will need to demonstrate that the controls surrounding those connections are developing as quickly as the technology itself.
The firms have already advised their clients to scrutinise suppliers, restrict permissions and understand where information is held.
Their own rapid AI expansion will test whether they are following that advice.
Because the security of a global AI platform will depend not only on the sophistication of the technology at its centre, but on the least protected system—or person—allowed to reach it.
This article forms part of Big4News’ ongoing series examining AI automation, hallucinations and risk across the Big Four.
Big Four AI: Automation, Hallucinations and Risk
Deloitte, PwC, EY and KPMG are investing heavily in AI, selling AI-enabled services to clients, and presenting themselves as trusted advisers on automation, governance and digital transformation. But the rise of generative AI also raises difficult questions about quality control, professional judgment, accountability and client reliance.
About Claudine Cassar
I’m a corporate anthropologist and former Deloitte equity partner. I sold my technology business to Deloitte in 2016 and led the Malta Consulting team for five years. I am the founder and editor of Big4News, which provides independent, clear analysis of PwC, Deloitte, EY, and KPMG — free from corporate spin.
Find me on LinkedIn, X, Instagram, or my author website.
Feel free to reply to this newsletter — I read every reply.








