Home/Incidents/Ernst & Young (EY Australia)

Ernst & Young (EY Australia)

22 Jul 2026 · National · Legal & Professional Services
Supply Chain Attack HIGH ✓ Verified

What happened

Ernst & Young issued formal breach disclosures to corporate clients after sensitive engagement data was compromised via a third-party software vendor. The breach involved unauthorized exfiltration of corporate files, client documentation, and internal project matrices managed within the external software tool. Core internal EY infrastructure remained uncompromised. EY engaged cyber forensic specialists, notified domestic privacy regulators, and instituted enhanced security controls across vendor software integrations.

Incident details

Organisation
Ernst & Young (EY Australia)
Date
22 Jul 2026
Attack type
Supply Chain Attack
Severity
HIGH
Sector
Legal & Professional Services
State
National
Records affected
Unknown
Threat actor
Unknown

Source

accountingtimes.com.au ↗
← Back to all incidents