Ernst & Young Client Data Stolen in Third-Party Platform Breach
Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

Key points
- Criminals stole names, home addresses, Social Security numbers, and credit and debit card numbers from an Ernst & Young-linked platform.
- The data was held not by Ernst & Young directly, but by a third-party management platform the firm relied on.
- Social Security numbers in the wrong hands can be used to open fraudulent loans or file false tax returns in a victim's name.
- SecurityWeek first reported details of the breach.
Ernst & Young, one of the world's largest accounting and professional-services firms, has confirmed that client personal and financial information was stolen after criminals broke into a third-party software platform, meaning a separate company's system that Ernst & Young had contracted to store or process data on its behalf.
The stolen records include names, home addresses, Social Security numbers (the unique nine-digit government ID numbers Americans use for taxes, banking, and benefits), and credit and debit card numbers. That combination is serious. It gives criminals nearly everything they need to open new accounts, take out loans, or file fraudulent tax returns in a victim's name.
What should affected people actually do?
If you are or were an Ernst & Young client, treat this as a prompt to act now rather than a reason to panic. Place a free credit freeze with all three major credit bureaus, Equifax, Experian, and TransUnion. A freeze stops lenders from opening new accounts in your name, even if someone has your Social Security number. It costs nothing and you can lift it temporarily whenever you need credit yourself.
Also check your bank and card statements for any charges you do not recognise, and watch your post for bills or letters about accounts you never opened.
For the breach itself, the detail that stands out is where the data was kept. It was not inside Ernst & Young's own systems. It sat with a third-party platform, a contractor or software vendor the firm used to handle certain management tasks. This matters because it shifts the initial point of failure outside the firm's direct walls.
Third-party breaches like this follow a pattern that has become familiar in CTI (cyber-threat intelligence, meaning the discipline of tracking how and why attackers operate) circles. Large professional-services firms outsource functions to specialist vendors. Those vendors sometimes hold data for dozens of major clients at once, making them attractive targets. One successful attack can expose data belonging to many organisations simultaneously.
At the time of writing, no specific hacking group has been publicly attributed to this incident, and no ransomware, meaning malicious software that locks files until a payment is made, has been linked to it. The method of intrusion has not been disclosed. Attribution claims made on thin evidence are worth little, and single-source attribution is worth less.
What is clear is the outcome: real personal and financial records, belonging to real people, are now outside anyone's control.



