Ernst & Young (EY) disclosed a data incident in July 2026 after detecting anomalous activity on April 23, 2026. The firm determined that a third party had accessed an IT service management platform used by its tax practice between March 28 and April 12, 2026. EY removed the unauthorized access and notified law enforcement, stating no evidence of data misuse was found. The incident potentially involved names, Social Security numbers, financial account codes, and credit/debit card information. While a full count of affected individuals is not publicly confirmed, at least 1,366 California residents were among those notified. Additional individuals in Texas, Massachusetts, and Vermont also received notifications. More details may emerge as investigations continue, and notifications to affected individuals may be ongoing or delayed.