US-based national class action law firm Edelson Lechtzin has started an investigation into potential data privacy claims stemming from a cybersecurity incident at EY.
According to an Edelson Lechtzin statement, the incident may have exposed personal and financial information contained in, or used to prepare, client tax filings.
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
The law firm stated it will assess individuals’ rights and possible claims “at no cost”.
EY began notifying affected clients this month after concluding that an unauthorised third party had accessed a third-party support ticket system used by its IT staff.
The company reported that it detected unusual activity on its networks on 23 April 2026. EY then launched an investigation, supported by external cybersecurity specialists.
According to the findings, the intruder accessed the third-party IT service management platform between 28 March 2026 and 12 April 2026.
The platform is used to support EY employees working on client tax services.
During this window, multiple documents belonging to a number of EY clients were downloaded by the intruder.
EY informed affected individuals via a filing with the California Department of Justice.
In that notice, the company said it had secured its systems, removed the unauthorised access and notified federal law enforcement.
Public reports indicate that EY has not disclosed how many clients were impacted, which third-party provider was involved, or whether the incident is confined to its US client base.
The breach may have compromised personal and financial details contained in, or relied on to prepare, client tax filings.
“Because tax records combine identifying and financial details, affected individuals may face an increased risk of identity theft, tax fraud, and targeted phishing or social engineering attacks,” Edelson Lechtzin said in the statement.
As of EY’s disclosure, no data extortion or ransomware group had publicly claimed responsibility. The company has not identified the threat actor behind the incident.
