Ernst & Young, one of the world’s largest accounting and tax firms, has begun telling clients that criminals made off with the personal records it keeps to prepare their tax returns. Those files rank among the most sensitive a household ever hands over: the Social Security numbers, financial account details and payment information that identity thieves need to open credit lines, file bogus refund claims and reach into existing accounts. For older Americans, whose retirement savings and predictable benefit deposits make them favored targets, a breach at a trusted preparer turns a routine tax relationship into a standing exposure.
What EY says was taken, and when
The firm has said the intrusion struck a third-party platform used to support tax work rather than EY’s own core systems, with unauthorized access running from late March into April of this year, according to SecurityWeek’s account of the breach notification. The information that may have been exposed includes names, mailing addresses, Social Security numbers, financial account numbers, payment-card details and investment information — the raw material a preparer assembles to build a return.
The route in underscores how exposed a tax relationship can be even when a firm’s own network holds. Because the stolen records sat on an outside platform that supported EY’s tax work, the affected clients had no practical way to know their most sensitive documents lived on a system they never chose and could not inspect. A vendor several steps removed from the household became the weak point, and the data that moved through it — gathered precisely because a return requires it — is the same data a criminal needs to impersonate the taxpayer.
EY has started notifying the people it believes were affected, and it is offering 24 months of identity monitoring and restoration services through Experian. Notification letters filed with state regulators identify affected residents across several states, and the count is expected to climb as the firm works through the records tied to the compromised platform.
The distinction between EY’s internal network and an outside support vendor matters less to the exposed clients than the nature of the data. A tax file is a one-stop identity kit, and a breach of it does not expire when the current filing season ends.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
The ShinyHunters extortion threat
The breach carries a second layer of pressure. The extortion group known as ShinyHunters has claimed responsibility, added EY to its dark-web leak site and threatened to publish the stolen material unless the firm makes contact, as reported by BleepingComputer. The group set a leak deadline of July 31.
Whether or not the data is dumped on the deadline, the calculus for an affected client does not change. Once records leave a controlled environment, they can be copied, sold and reused for years. Treating the exposure as permanent, rather than tied to any single leak date, is the safer posture.
Why a stolen Social Security number is the dangerous part
Payment cards can be canceled and reissued in a day. A Social Security number cannot. It is the fixed key that lenders, the tax system and government programs use to identify a person, which is exactly why criminals prize it. With a name, address and Social Security number in hand, a thief can attempt to open new credit cards or loans, file a fraudulent tax return to intercept a refund, or apply for benefits in someone else’s name.
Retirees face a particular version of this risk. Fraudulent returns filed early in a season can beat a legitimate filer to the refund, and new accounts opened in a retiree’s name can surface only when a collections notice arrives months later. The damage is often quiet at first and expensive to unwind.
The tax-return angle a preparer breach opens
A breach at a tax firm is uniquely suited to refund fraud, because the stolen files already hold the exact information a fraudulent return needs: a name, a Social Security number, an address and prior-year financial details that help a bogus filing slip past automated screening. A criminal who files early in the season, before the real taxpayer submits, can route a refund to an account or prepaid card the thief controls, and the legitimate filer often discovers the theft only when the IRS rejects a return as already filed under that number.
One federal tool closes that specific door. The IRS issues a six-digit Identity Protection PIN that a taxpayer places on a return, and without the current year’s code the agency will not accept an electronically filed return under that Social Security number — which blocks an impostor from filing first. The PIN refreshes each year and works alongside a credit freeze: the freeze guards against new accounts, the PIN guards the refund.
Steps that limit the damage
The federal government’s identity theft recovery site walks people through the concrete moves that matter after an exposure: reporting the theft, disputing fraudulent accounts and building a documented recovery plan. Anyone who receives a notification letter can act on it even before the deadline threats play out.
The single most effective preventive step is a credit freeze. A freeze locks new lenders out of a person’s credit file, so a thief holding a stolen Social Security number cannot open accounts in that name. The Federal Trade Commission notes that a credit freeze is free to place and lift at each of the three national credit bureaus and does not affect a person’s credit score. A freeze can be lifted temporarily when a genuine loan or card application is planned, then reinstated. For a household that is not shopping for new credit — which describes many retirees — leaving the freeze in place indefinitely closes the door that a breach like this one otherwise leaves open.
This article was researched and drafted with AI assistance and reviewed against the linked primary sources.
More Financial Reading
- How many CDs can you park at 1 bank? FDIC rules you must know
- What really happens to your joint savings account when you die?



