Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Priority Intake
Cybersecurity

A Big Four firm lost client tax records through its help desk. Yours has one too.

Aug 19, 2026·4 min read·By Ric Acevedo

On 15 July, Ernst & Young filed breach notifications with the California and Texas Attorneys General. An unauthorised party had been inside a support ticket platform used by EY’s IT help desk between 28 March and 12 April, downloading documents attached to those tickets. EY spotted the activity on 23 April — twenty-six days after it began.

The documents contained names, home addresses, Social Security numbers, bank account numbers, card numbers, and tax preparation files.

Here is the part worth sitting with, and it is not the part most coverage led with.

It wasn’t the audit systems. It was the help desk.

Nobody broke into EY’s tax software. Nobody defeated the controls around their audit practice. Someone got into the platform where support tickets live — and the reason that mattered is that people attach things to support tickets.

Think about what lands in your own help desk in February. A client can’t open a PDF, so they email it to you. Someone’s return won’t upload, so they attach it to the ticket. A bookkeeper sends a bank statement to prove the reconciliation is off. None of that is a system of record. All of it is client data, and it sits in whatever tool you use to track the request.

That is the blind spot. Firms secure the software they think of as holding client data, and quietly accumulate a second copy of it somewhere nobody classified as sensitive.

Three things about the timeline

Twenty-six days to notice. Access began 28 March and was identified 23 April. This is a firm with a security budget larger than most of our clients’ annual revenue.

Eighty-three days to disclose. Detected 23 April, filed 15 July. If you are an EY client, you spent nearly three months not knowing.

The count is still not public. EY has not disclosed how many individuals were affected, and has not named the platform.

We are not writing this to criticise EY’s response. We are writing it because the mechanism — a third party holding documents nobody was auditing — is the single most common gap we find, and it is almost never on anyone’s list.

The requirement most small firms skip

If you prepare returns, the FTC Safeguards Rule already applies to you. It has six core requirements, and the one nearly every small practice skips is vendor oversight — holding every provider who touches client data to the same standard you hold yourself.

Your help desk tool is a vendor. So is your document portal, your cloud backup, your practice management software, and increasingly whatever AI assistant someone on staff connected to their work account.

And when you renew your PTIN this autumn, Form W-12 is signed under penalty of perjury. Line 11 is where you confirm your data security responsibilities — that you have a written information security plan, and that your practice follows it. Vendor oversight is part of what you are confirming.

What we would actually do about it

None of this requires buying anything from us.

  1. List every service that can see client data. Not the ones you pay for — the ones with access. Most firms find two or three they had forgotten about.
  2. Check what has been connected to your Microsoft 365 or Google account. Staff sign into tools with their work login and click Accept, and that tool keeps a token against your mail or files indefinitely. There is no alert and no expiry. We ran this check on our own company and found ChatGPT holding read access to every file we own. We removed it the same day.
  3. Ask your help desk and portal vendors two questions: how long do attachments live, and who on your side can read them.
  4. Write the plan down. The IRS publishes the template free as Publication 5708. You do not need to buy that from anyone, and we would be wary of whoever tries to sell it to you.

The document is the easy half. Being able to say your practice actually follows it — that is the half that takes work, and it is the half Line 11 asks about.

If it would help to have someone look at where your firm genuinely stands before October, there is a short self-check here. It takes a couple of minutes and costs nothing.

Sources: breach notifications filed with the California and Texas Attorneys General, 15 July 2026; reporting by BleepingComputer and SecurityAffairs. The ShinyHunters extortion group has claimed responsibility; EY has not confirmed attribution.

Recent Articles

Invoice Fraud: The Scam That Targets Your Accounting Team (Not Your IT)
Business IT
Invoice Fraud: The Scam That Targets Your Accounting Team (Not Your IT)
Jul 19, 2026
Renewing your PTIN this fall? Line 11 asks more than most preparers realize
Cybersecurity
Renewing your PTIN this fall? Line 11 asks more than most preparers realize
Jul 17, 2026
Is ChatGPT HIPAA Compliant for a Medical or Dental Practice?
Cybersecurity
Is ChatGPT HIPAA Compliant for a Medical or Dental Practice?
Jul 13, 2026
Federal Agencies Say AI Cyberattacks Are Months Away, Not Years. Here's What That Means for Your Business.
Cybersecurity
Federal Agencies Say AI Cyberattacks Are Months Away, Not Years. Here's What That Means for Your Business.
Jul 8, 2026
Voice Cloning Scams: The 2026 Attack Targeting Small Business Owners
Business IT
Voice Cloning Scams: The 2026 Attack Targeting Small Business Owners
Jun 15, 2026

Related posts

Digital Business Card