Ernst & Young issued formal breach disclosures to corporate clients after sensitive engagement data was compromised via a third-party software vendor. The breach involved unauthorized exfiltration of corporate files, client documentation, and internal project matrices managed within the external software tool. Core internal EY infrastructure remained uncompromised. EY engaged cyber forensic specialists, notified domestic privacy regulators, and instituted enhanced security controls across vendor software integrations.