Back to Exposure Report
Professional ServicesJuly 2026Global

Ernst & Young

A Big Four firm audits other companies' controls for a living. Its own exposure came through a platform it did not build, holding data it did not generate.

Social Security numbersNames and addressesCredit and debit card numbersOther personal and financial information
1

What happened?

Ernst & Young disclosed a data breach involving a third-party management platform. The ShinyHunters extortion gang claimed responsibility, stating it obtained credentials for some of the firm's systems through a supply-chain attack.

EY is offering affected individuals two years of free credit monitoring, identity monitoring, and identity restoration services. The number of affected individuals has not been publicly disclosed as of this writing. ShinyHunters has been the most active extortion operation of 2026, with a documented pattern of SaaS-tenant compromise; Microsoft published guidance in July on defending against the group's OAuth abuse techniques.

2

What data was actually inside?

Per EY's disclosure, the stolen data includes names, addresses, Social Security numbers, credit and debit card numbers, and other personal and financial information.

Social Security numbers and payment card numbers in the same record set is an unusually damaging combination, and it is worth being precise about why. An SSN enables identity-level fraud that persists for years and cannot be reissued in practice. A card number enables immediate financial fraud but is trivially cancelled. Exposed together, the victim faces both the fast attack and the slow one, and remediating the first does nothing about the second.

3

Who gets hurt and how?

The individuals in these records are largely not EY employees. Professional services firms hold data belonging to clients and, in many engagements, to their clients' customers and workforces — payroll populations in a tax engagement, plan participants in a benefits audit, claimants in a forensic matter.

None of those people selected the platform. Most did not know their information had been transferred to a Big Four firm at all, let alone onward into a vendor tool supporting the engagement. They have no relationship to leverage, no account to secure, and no way to have assessed the risk in advance. They will learn the platform existed from a notification letter. With SSNs exposed, the realistic harms are fraudulent tax filings and new-account fraud; with card numbers, direct fraud until reissue.

4

What did they think they were doing right?

EY is a firm whose business includes assessing whether other organizations' internal controls are adequate. Its own control environment, third-party risk program, and vendor due diligence are unquestionably formal, documented, and audited — professional services firms are contractually obligated to demonstrate exactly that to win engagements.

Third-party risk management is the control that was in place, and this is precisely the failure mode it does not address. Vendor due diligence evaluates a supplier's security posture at a point in time. It produces a questionnaire response, a SOC 2 report, and a contractual commitment. What it does not produce is an ongoing record of which datasets your engagement teams have actually loaded into that vendor's platform since the assessment closed.

5

What did they not know about their own data?

Professional services has a structural data problem that most industries do not. Data arrives continuously, from hundreds or thousands of separate engagements, each with its own scope, its own client, its own retention terms, and its own tooling chosen by the partner running it. The firm does not generate this data. It receives it, processes it, and is then obligated to hold or dispose of it under engagement-specific terms.

Multiply that across a global partnership and the question "which platform holds regulated personal data from which engagement?" has no single owner and no central answer. A third-party management platform is exactly the kind of system that accumulates this exhaust — procured centrally, used broadly, populated by whoever needed it, and never re-inventoried.

The firm that certifies whether your controls are adequate is running the same vendor sprawl you are, for the same reason: nobody's job description includes counting it.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Attribution here is unusually tangled because EY is, for most of this data, not the originating controller. Determining who to notify requires first determining which client engagement each record came from, then reading the engagement terms to establish whether EY notifies directly or the client does, then applying the breach statute of each affected individual's jurisdiction.

Because SSNs and card numbers are involved, effectively every US state statute is triggered, including California's 30-day notification requirement under SB 446 effective January 1, 2026 — filings surface on the California AG breach list. Any EU personal data engages GDPR's 72-hour supervisory authority deadline. Running alongside all of it is a client-notification exercise with no legal deadline and severe commercial consequences: every affected client must be told that its data was in the platform, which requires knowing, per client, exactly what was there.

7

What would have changed the outcome?

A record of which engagement's data landed in which platform, maintained as the data moved — so that "whose records were in there?" is a lookup rather than a project.

Vendor questionnaires assess the supplier. They do not track the data. Every engagement a firm accepts brings information it now holds and must eventually answer for, and the answer degrades from the moment the engagement closes and the team moves on. The organizations that handle a supply-chain compromise well are not the ones with the strictest procurement gate; they are the ones who can still say, two years later, exactly which dataset went where. See also the Brinks Home Salesforce listing, another ShinyHunters operation against a platform the victim did not build.

Ernst & Young found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.