EY faces proposed US class action over client data breach
Lawsuit alleges EY failed to protect sensitive tax, financial and personal information exposed through a third-party IT support platform
EY is facing a proposed class action in the United States over a cybersecurity breach that exposed sensitive information held in an IT support-ticket system used by the firm’s tax teams.
The lawsuit was filed in the US District Court for the Southern District of New York by Illinois resident Markishi Wyatt, who says her information was compromised. She is seeking to represent all affected individuals in the United States and is claiming monetary relief on their behalf.
EY detected anomalous activity on the third-party platform on 23 April 2026. Its investigation found that an unauthorised party had accessed the system between 28 March and 12 April and downloaded documents relating to a number of clients. Support tickets stored on the platform could include attachments containing tax information.
The information potentially exposed included names, addresses, Social Security numbers, financial-account details and information contained in, or used to prepare, tax filings. The number of affected individuals has not been publicly disclosed.
The complaint alleges that EY failed to maintain adequate cybersecurity safeguards despite the sensitivity of the information entrusted to it. It argues that affected individuals now face an increased risk of identity theft, financial fraud and tax fraud. These remain allegations that EY has not admitted.
EY has said it contained the incident, secured its systems, engaged independent cybersecurity specialists and notified law enforcement and affected clients. The firm said it was not aware of any misuse of the compromised information and offered eligible individuals 24 months of identity-monitoring and restoration services.
Related coverage
EY hit with proposed class action over data breach — CFO Dive, 21 July 2026
Reports on the filing of the lawsuit and summarises the plaintiff’s claims that EY failed to protect highly sensitive client tax and financial information.
Ernst & Young Data Breach Affects Personal, Financial Information — SecurityWeek, 20 July 2026
Details the categories of information potentially exposed, including Social Security numbers, payment-card information and financial-account data.
Ernst & Young reveals data breach following hack on support system — TechRadar Pro, 20 July 2026
Explains how attackers gained access through a third-party IT service-management platform and downloaded documents over a two-week period.
Edelson Lechtzin reviews potential claims over EY tax data breach — International Accounting Bulletin, July 2026
Covers a separate law-firm investigation into possible privacy claims arising from the breach and the exposure of information used in client tax filings.
EY tells clients of third-party data breach — Accounting Times, 22 July 2026
Provides a concise account of EY’s notification to clients and the period during which the attacker accessed and removed data.
This article forms part of the Big4News series examining AI automation, hallucinations and risk across the Big Four.
Big Four AI: Automation, Hallucinations and Risk
Deloitte, PwC, EY and KPMG are investing heavily in AI, selling AI-enabled services to clients, and presenting themselves as trusted advisers on automation, governance and digital transformation. But the rise of generative AI also raises difficult questions about quality control, professional judgment, accountability and client reliance.
Want to stay up to date on all things Big Four around the world?
Check out the News section and subscribe to Big4News for weekly deep dives and briefings.




