EY data breach hits Big Four security
Unauthorized access to IT platform impacts clients including Goldman Sachs and Man Group, prompting regulatory notifications in the US.
Quick Look
EY disclosed a data breach occurring between March and April 2026, where an unauthorized party accessed an IT platform via a Checkmarx software vulnerability, exposing sensitive tax-related client documents and triggering regulatory filings in four US states.
AI-generated summary
Why It Matters
EY has experienced previous security incidents, including the 2023 MOVEit breach. The firm operates with a federated global network structure that complicates uniform security implementation.
Mumbai: The EY data breach that exposed potentially sensitive client information linked to Goldman Sachs and Man Group has put the spotlight on data security at top professional services firms. This comes as audit committees and technology chiefs at these companies demand tighter controls over confidential client data, employee access, artificial intelligence tools and third-party software.
In a recent email to affected clients, EY said an unauthorised third party accessed a platform used by its IT teams between March 28 and April 12, 2026, and downloaded documents pertaining to several clients, potentially exposing sensitive information related to its tax services. The larger hack was linked to a vulnerability in Checkmarx software, the company said.
In India, a large professional services firm experienced a data breach in its GST software after a developer copied code from a public source that contained a backdoor. Such instances frequently go unreported or undetected due to lax disclosure standards and inadequate regulatory oversight, said experts.
In the EY case, the firm had to notify regulators in four US jurisdictions - California, Texas, Massachusetts and Vermont - about the 2026 data breach.
The Big Four professional services firms have faced multiple data breaches and security vulnerabilities in recent years, and the growing use of AI, alongside increasingly sophisticated cyberattacks, is likely to intensify the risks, experts said.
EY's 2023 MOVEit breach led to alerts to 30,210 Bank of America clients, while PwC disclosed it was also hit by the same attack. Previously, KPMG Mexico reported that client employee and tax data were exposed online.
An EY spokesperson said the current incident "did not impact broader EY enterprise systems and presents no threat to ongoing business".
The company added: "EY has conducted a comprehensive review of the affected data and the investigation is now in its final stages. We have been communicating the results of our analysis directly to clients as the review process concludes."
Senior partners in charge of technology at the Big Four firms told ET that their complex technology architecture and highly interconnected global networks could create risks, especially as more work and sensitive client information flow through digital systems.
One of the biggest potential weak points is the communication channel between firms and their clients, they said.
Much of the work, particularly in India, is conducted over email. In some cases, clients may use consumer email services such as Gmail, creating another layer of risk in how sensitive information is exchanged and stored.
The global networks of the Big Four are also not a single, uniform technology environment. "Their networks have a federated structure, with different member firms and geographies operating systems at different levels of sophistication and integration. This can create gaps in security standards and controls across the network," said a senior partner at a Big Four firm.
Lately, some of the largest networks have been moving their major member firms onto more integrated technology platforms, but the transition is not complete. The continued presence of multiple networks and legacy systems can make it harder to maintain uniform security controls across the organisation.
Treating cybersecurity as confined to an enterprise's boundaries can create blind spots as client data move across member firms and external providers, said Apeksha Kaushik, senior principal analyst at technology research firm Gartner. "The practical priority is to create a consistent, measurable security baseline across all member firms and critical providers, while allowing local teams to adapt implementation to their regulatory and operational context."
Another potential vulnerability lies in how information is stored and accessed across member firms. Sensitive information may be held in different systems and jurisdictions, while access can extend across parts of the wider network. "A security weakness in one global member firm can have implications beyond its own geography. Indian firms have been raising this issue with the ICAI (Institute of Chartered Accountants of India) and other stakeholders, but there has been little response. This is a core issue of national interest," said the CEO of an Indian chartered accountancy firm, speaking on the condition of anonymity.
Open Questions
- What specific tax data was compromised?
- Will there be legal repercussions from the affected US states?

