Urgent.News

What's breaking now, across thousands of outlets.

Tech

EY data breach hits Big Four security

Mumbai: The accounting giant EY has disclosed a data breach that exposed potentially sensitive client information linked to prominent firms such as Goldman Sachs and Man Group. The unauthorized third-party access to a platform used by EY's IT teams between March 28 and April 12, 2026, resulted in the download of documents pertaining to several clients, potentially exposing sensitive tax-related data.

The breach was traced back to a vulnerability in Checkmarx software. EY notified regulators in four US states - California, Texas, Massachusetts, and Vermont - about the incident. The Big Four professional services firms, including EY, PwC, and KPMG, have experienced multiple data breaches and security vulnerabilities in recent years, with the rising use of AI amplifying these risks.

During the EY 2023 MOVEit breach, 30,210 Bank of America clients were alerted to the issue. EY's spokesperson assured clients that the current breach did not compromise broader EY enterprise systems and posed no threat to ongoing business. The company has conducted a comprehensive review of the affected data, with the investigation nearing completion.

Senior technology executives from the Big Four firms expressed concerns over the complex technology architecture and interconnected global networks, highlighting the communication channel between firms and clients as a potential weak point. Many client communications, especially in India, occur via email services like Gmail, further increasing the risk of sensitive information being exchanged and stored.

The Big Four's global networks, characterized by different member firms and geographies, operate on various technology levels, creating gaps in security standards and controls. As firms transition to more integrated technology platforms, the continued presence of legacy systems complicates maintaining uniform security measures across the organization.

Experts emphasize the need for a consistent, measurable security baseline across all member firms and external providers while allowing local teams to adapt implementations to regulatory and operational contexts. Indian firms have been advocating for improved cybersecurity standards with the ICAI and other stakeholders, but progress has been limited. This issue is deemed a core national concern by an Indian chartered accountancy firm's CEO.

Written by urgent.news from The Economic Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at economictimes.indiatimes.com →

More in Tech

Apollo GraphOS Agent Services: Apollo Agrees Agents Need Explicit Rules — But Governance Stops at Access

Apollo GraphOS Agent Services: Apollo Agrees Agents Need Explicit Rules — But Governance Stops at Access On October 7, 2026, Apollo GraphQL launched GraphOS Agent Services at Apollo Summit in San…

  • Apollo GraphOS Agent Services launched Oct 7, 2026, at Apollo Summit
  • Rules for safe returns need explicit definition, not API judgment
  • Governance stops at access, not financial decision-making

Implementing a JSON Parser

Ever wondered how applications understand and process data from APIs? The magic often lies in a data format called JSON. This human-readable format is widely used to transmit data over the internet.

  • JSON parser implemented using Deno and TypeScript
  • Tokenizing breaks JSON into meaningful tokens
  • Parsing creates Abstract Syntax Tree for structured data

Validate Google Hotel Center, Wego and trivago hotel feeds from CI

Validate Google Hotel Center, Wego and trivago hotel feeds from CI Hotel distribution feeds look simple until you need to send the same property data to multiple platforms.

  • Open-source CLI tool validates Google Hotel Center, Wego, trivago feeds.
  • Supports published-contract validation and readiness checks for platforms.
  • CLI integrates into CI pipelines for automated feed quality checks.

More from Friday 9 October →