Vendor dossier // ey.com
Also known as Ernst & Young · Ernst & Whinney · Arthur Young & Co.
London, United Kingdom · Est. 1989 · 10,001+ employees
Key people
Last updated: Jul 29, 2026, 10:31 PM · Partial / limited public data
Do not proceed
EY is classified as High Risk due to a recent, material data breach disclosed in July 2026. The incident involved unauthorized access to a third-party IT… Limited public data — verify before relying.
Risk Tier
Risk Score
Confidence
partial
Material Incidents
Ernst & Young Global Limited (EY) is a leading global professional services firm headquartered in London, United Kingdom, founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co. With over 10,000 employees and annual revenue of approximately $53.2 billion, EY provides a comprehensive suite of services including assurance, tax advisory, transaction consulting, and digital transformation. The firm operates worldwide and maintains a significant presence across North America, Europe, and Asia. EY emphasizes continuous skills development through initiatives like the EY Tech MBA and EY Badges program, preparing its workforce for future-focused technology and sustainability challenges. As a member of the Big Four accounting firms, EY serves a diverse client base spanning public and private sectors.
EY delivers a range of proprietary technology platforms and consulting solutions designed to accelerate digital transformation and strategic decision-making. Key offerings include EY-Parthenon Competitive Edge, an AI-led M&A and strategic intelligence platform that scans markets for disruption opportunities and competitor analysis. The firm also provides EY Risk Navigator for predictive analytics in risk and compliance monitoring, and the EY Trusted AI Platform to evaluate and quantify AI impact and trustworthiness. Additionally, EY's ey.ai orchestrates innovation through strategic alliances with major technology vendors like Microsoft, IBM, Adobe, and Snowflake. EY also supports low-code/no-code development to enable rapid, customizable application updates and API integrations for clients.
EY states that its global technology products, services, and data centers undergo independent third-party compliance audits against ISO 27001 standards to ensure information security management. The firm maintains a global cyber response framework and offers privacy litigation compliance and business continuity planning services. However, EY's security posture was recently challenged by a significant incident involving a third-party IT service management platform. The firm relies on data protection technologies aligned with applicable privacy laws and regulatory requirements. Despite these controls, the compromise of an external vendor platform highlights ongoing third-party risk management challenges, prompting EY to enhance incident response procedures and notify affected stakeholders regarding exposed client records.
[breach] EY Third-Party IT Support Platform Data Breach
Unauthorized access to a third-party IT service management platform between March 28 and April 12, 2026, exposed client tax, financial, and personal information. EY detected activity on April 23, 2026, and filed breach notifications in July 2026.
Jul 15, 2026, 12:00 AM · Source
Vendors offering a similar product or service - for side-by-side comparison, not a ranking.
Accenture
accenture.com
Deloitte
deloitte.com
PwC
pwc.com
KPMG
kpmg.com
In July 2026, EY publicly disclosed a major data breach following the unauthorized access of a third-party IT support ticket system used by its tax practice personnel. The intrusion occurred between March 28 and April 12, 2026, during which attackers downloaded documents containing client tax information, Social Security numbers, and financial account codes. EY detected anomalous activity on April 23, 2026, and immediately initiated its incident response protocol. The firm filed breach notifications with multiple state Attorneys General, including California and Vermont. This incident marks EY's third significant security breach in under three years linked to third-party vendors, resulting in a proposed class-action lawsuit and heightened scrutiny over the firm's vendor risk management practices.
Content in this section is vendor-supplied and does not alter Vendorisk.ai's risk tier or evaluation.
No input sources recorded · Generated Jul 29, 2026, 10:31 PM
Every verdict stores the public sources retrieved for this run. Read our methodology.
No input sources were recorded for this evaluation.
AI-generated assessment based on publicly available sources. Verify critical findings before contractual reliance. Analysis is advisory, not a compliance attestation, and is subject to data availability.
Years in Business
37 yrs
EY is classified as High Risk due to a recent, material data breach disclosed in July 2026. The incident involved unauthorized access to a third-party IT support platform, exposing sensitive client tax documents, Social Security numbers, and financial account codes. The breach triggered state regulatory notifications and a proposed class-action lawsuit. Given the active nature of the incident within the last 12 months, the exposure of highly sensitive personal and financial data, and the firm's history of repeated third-party vendor compromises, the risk profile meets the criteria for a High Risk tier.