Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Reviewing financial compliance documents and audit records

EY Breach Exposes Client Tax Data — A Warning for Wealth Management Firms

Ernst & Young has disclosed a data breach after an attacker accessed a third-party IT support platform used by EY staff working on client tax services. The attacker had access from 28 March to 12 April 2026 — more than two weeks — and downloaded documents containing names, addresses, Social Security numbers, account numbers, and tax filing records. EY didn’t detect the activity until 23 April, and only disclosed it publicly in July.

Why This Matters for Australian Wealth Management Firms

The breach didn’t happen in EY’s core systems. It happened in a support ticket platform — the kind of secondary system that rarely gets the same security scrutiny as a CRM or portfolio management tool. That’s the pattern worth paying attention to.

Australian wealth management firms routinely share sensitive client data with external parties: accountants, auditors, compliance consultants, licensee groups, and platform providers. In our work with financial services clients across Sydney and Central West NSW, we regularly see tax file numbers, portfolio valuations, and SMSF administration records flowing through vendor support portals, shared email inboxes, and ad-hoc cloud folders — channels with no IT governance, no access logging, and no breach notification obligations written into the arrangement.

Under APP 8 of the Privacy Act 1988, an Australian business that discloses personal information to a third party remains accountable if that third party mishandles the data — regardless of where the breach occurs.

The EY breach is what happens when one of those handoffs fails. And with maximum penalties under the Privacy and Other Legislation Amendment Act 2024 now reaching $50 million for serious or repeated breaches, the cost of an ungoverned data flow to a third-party provider has gone up considerably.

What to Do Now

  • Map every third-party provider that receives or can access client financial data, including support ticket systems, document portals, and shared drives
  • Confirm each vendor’s data handling terms, breach notification process, and security posture
  • Review access controls — who in your practice can share client data externally, and through which channels
  • Include third-party data flows in your annual Privacy Act compliance review

How All IT Works with Financial Services Firms

All IT works with wealth management firms and financial advisory practices to map data flows to third-party providers, assess vendor security posture, and maintain compliance under the Privacy Act. If you haven’t reviewed where client data goes once it leaves your systems, that’s a practical starting point. See our financial services IT, cybersecurity services, and managed IT support.

Written by Caleb Attard, All IT Services. All IT is an Australian managed IT provider supporting financial services businesses, hospitality groups, and not-for-profits across Sydney, Central West NSW, Brisbane, and Melbourne.


Not Sure Where Client Data Goes After It Leaves Your Systems?

All IT maps data flows, reviews vendor security, and maintains Privacy Act compliance for financial services firms. Monthly contracts, no lock-in.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →