EY Breach Exposes Client Tax Data — A Warning for Wealth Management Firms
Ernst & Young has disclosed a data breach after an attacker accessed a third-party IT support platform used by EY staff working on client tax services. The attacker had access from 28 March to 12 April 2026 — more than two weeks — and downloaded documents containing names, addresses, Social Security numbers, account numbers, and tax filing records. EY didn’t detect the activity until 23 April, and only disclosed it publicly in July.
Why This Matters for Australian Wealth Management Firms
The breach didn’t happen in EY’s core systems. It happened in a support ticket platform — the kind of secondary system that rarely gets the same security scrutiny as a CRM or portfolio management tool. That’s the pattern worth paying attention to.
Australian wealth management firms routinely share sensitive client data with external parties: accountants, auditors, compliance consultants, licensee groups, and platform providers. In our work with financial services clients across Sydney and Central West NSW, we regularly see tax file numbers, portfolio valuations, and SMSF administration records flowing through vendor support portals, shared email inboxes, and ad-hoc cloud folders — channels with no IT governance, no access logging, and no breach notification obligations written into the arrangement.
The EY breach is what happens when one of those handoffs fails. And with maximum penalties under the Privacy and Other Legislation Amendment Act 2024 now reaching $50 million for serious or repeated breaches, the cost of an ungoverned data flow to a third-party provider has gone up considerably.
What to Do Now
- Map every third-party provider that receives or can access client financial data, including support ticket systems, document portals, and shared drives
- Confirm each vendor’s data handling terms, breach notification process, and security posture
- Review access controls — who in your practice can share client data externally, and through which channels
- Include third-party data flows in your annual Privacy Act compliance review
How All IT Works with Financial Services Firms
All IT works with wealth management firms and financial advisory practices to map data flows to third-party providers, assess vendor security posture, and maintain compliance under the Privacy Act. If you haven’t reviewed where client data goes once it leaves your systems, that’s a practical starting point. See our financial services IT, cybersecurity services, and managed IT support.
Not Sure Where Client Data Goes After It Leaves Your Systems?
All IT maps data flows, reviews vendor security, and maintains Privacy Act compliance for financial services firms. Monthly contracts, no lock-in.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
