news.mlab.sh
Back to the feed
data-breach

Ernst & Young Data Breach Affects Personal, Financial Information

High
Summary

Ernst & Young (EY) experienced a data breach affecting the personal and financial information of its clients due to a vulnerability in a third-party service management platform. The breach, discovered in April, exposed sensitive data including Social Security numbers and credit card details, and EY is offering affected clients two years of credit monitoring services.

Ernst & Young (EY), a leading professional services firm, has been notified that a data breach compromised the personal and financial information of its clients. The incident was initially discovered on April 23rd and stemmed from a vulnerability within a third-party service management platform utilized by EY to support tax-related work for its clients. In a notification letter, EY stated that support tickets submitted through the platform could contain documents containing client tax information. Following the detection of anomalous activity, EY activated its incident response team and initiated remediation and recovery efforts, engaging an independent cybersecurity firm to investigate the scope and nature of the attack. The attackers reportedly gained access to the platform between March 28 and April 12, downloading documents containing sensitive client data, including names, addresses, Social Security numbers, account numbers, and credit/debit card details. EY has not yet disclosed how the breach occurred or the identity of the threat actor involved, and no ransomware group has claimed responsibility for the incident. The company is currently providing affected clients with two years of free credit monitoring, identity monitoring, and identity restoration services as a mitigation measure.

Read the full article at SecurityWeek