ZDNET58%

Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next 19%

By Charlie Osborne43%

7/21/2026, 3:30:52 PM

BS Summary: This article contains 12 faulty reasoning types, including Indoctrination, Availability Heuristic, and Optimism Bias, with Attempt to Sell a Product or Service as the most egregious example at 8.1% saturation with 52 hits. Analysis detected 401 faulty-reasoning hits from 644 analyzed words, generating a BS Score of 34.3% and a BS Rank of 19% (15,884 of 19,502 articles). This article is better (less manipulative) than 81.40% of the article peer group.

Ernst & Young has disclosed a data breach that resulted in the theft of clients' personal information. 
From March 28 to April 12, attackers had access to a third-party support ticket system containing customer information related to their tax affairs. 
Also: Is that QR code a trap? 
How to spot quishing scams before it's too late 
A ticket support system becomes the target 
A data breach notice was filed with the California Attorney General's office on July 15, as well as other states, including Massachusetts and Vermont. 
Ernst & Young has since begun notifying customers of the security incident. 
According to the organization's notice to clients [PDF], the data breach was caused by an intrusion into a third-party IT platform that Ernst & Young uses to handle tax-related work for clients. 
The support system allows Ernst & Young teams to submit support tickets, which may contain sensitive customer information. 
Also: I connected ChatGPT to my bank, and it's my go-to finance app now - here's how (and why) 
For roughly two weeks in March and April, the cybercriminal responsible for the breach was able to download records "pertaining to a number of EY clients," according to the notice. 
Ernst & Young detected suspicious activity on the platform on April 23 and hired a cybersecurity firm to investigate the incident. 
The support ticket system has now been secured, although no further details -- on the compromise, any use of malware, or the responsible party -- have been disclosed. 
What personal customer data is at risk? 
Ernst & Young says in the notification letter that "certain financial information contained in or used to prepare tax filings" and the sample notice includes a placeholder for customers' specific data points. 
The Big Four accounting firm has not disclosed exactly what records were leaked. 
It is possible that personal, sensitive data necessary for tax filing could be included, such as names, addresses, Social Security numbers, financial account information, and other records, but until Ernst & Young formally discloses this information, we can't be sure. 
Also: The 10-step phone security tune-up you should run every year - and why 
EY added in the notice that the organization is "not aware of any misuse or further exposure of [your] personal information as a result of this incident," and also says there is no "indication [your] personal information was specifically targeted." 
How do I know if I'm impacted? 
If you have received a letter from Ernst & Young notifying you of the data breach, it should list the sensitive and financial information that has been stolen. 
As we do not know how many clients have been affected, it's also not possible to say whether every victim has received their letter yet. 
If you haven't seen one, this doesn't mean that you're in the clear. 
Ernst & Young is offering 24 months of two free Experian services for affected customers: IdentityWorks and Identity Restoration, which, combined, can be used for credit monitoring and restoration. 
You will need to visit Experian's website and use the code contained in your letter to activate these services before October 31, 2026. 
Also: LastPass hit by new data breach - 4 steps you should take now 
You should also keep a close eye on your accounts and credit report for any suspicious activity or fraudulent transactions, and you may want to consider freezing your credit for now until more is known about the scale of the incident. 
As this data breach involves the theft of tax-related financial information, another measure you should consider to protect yourself is to sign up for an IRS identity protection PIN. 
This will prevent anyone from filing a tax return on your behalf using your Social Security number or individual taxpayer identification number. 
Confirmation Bias
0%
Anchoring Bias
0%
Availability Heuristic
6.2%
Representativeness Heuristic
0%
Hindsight Bias
0%
Overconfidence Bias
0%
Framing Effect
0%
Loss Aversion
3.6%
Status Quo Bias
0%
Sunk Cost Effect
0%
Optimism Bias
6.2%
Pessimism Bias
0%
Negativity Bias
0%
Self-Serving Bias
0%
Fundamental Attribution Error
0%
Actor-Observer Bias
0%
In-Group Bias
0%
Out-Group Homogeneity Bias
0%
Halo Effect
0%
Horn Effect
0%
Dunning-Kruger Effect
0%
Recency Bias
0%
Primacy Effect
0%
Blind-Spot Bias
0%
Ad Hominem
0%
Straw Man
0%
Appeal to Authority
6.2%
False Dilemma
4.3%
Slippery Slope
0%
Circular Reasoning
0%
Hasty Generalization
6.2%
Red Herring
0%
Bandwagon
0%
Appeal to Emotion
1.1%
Begging the Question
0%
Post Hoc (False Cause)
0%
Tu Quoque
0%
Burden of Proof
4.7%
Appeal to Nature
0%
Composition/Division
0%
Anecdotal
3%
No True Scotsman
0%
Ambiguity (Equivocation)
5%
Gambler’s Fallacy
0%
Middle Ground
0%
Personal Incredulity
0%
Special Pleading
0%
Genetic Fallacy
0%
Unattributed Quote
0%
Quote-first Misdirection
0%
Biased Writer Voice
0%
Indoctrination
7.8%
Politically Left Leaning Bias
0%
Politically Right Leaning Bias
0%
Attempt to Sell a Product or Service
8.1%

644 words analyzed.

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.