{
  "id": 13178494,
  "title": "EY data breach hits Big Four security",
  "url": "https://urgent.news/2026/10/09/ey-data-breach-hits-big-four-security",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T18:25:22.000Z",
  "source": {
    "name": "The Economic Times",
    "slug": "the-economic-times",
    "url": "https://economictimes.indiatimes.com/news/company/corporate-trends/ey-data-breach-puts-spotlight-on-data-security-at-big-four-as-clients-demand-tighter-controls/articleshow/134840789.cms"
  },
  "original_language": "en",
  "account": "Mumbai: The accounting giant EY has disclosed a data breach that exposed potentially sensitive client information linked to prominent firms such as Goldman Sachs and Man Group. The unauthorized third-party access to a platform used by EY's IT teams between March 28 and April 12, 2026, resulted in the download of documents pertaining to several clients, potentially exposing sensitive tax-related data. The breach was traced back to a vulnerability in Checkmarx software. EY notified regulators in four US states - California, Texas, Massachusetts, and Vermont - about the incident. The Big Four professional services firms, including EY, PwC, and KPMG, have experienced multiple data breaches and security vulnerabilities in recent years, with the rising use of AI amplifying these risks. During the EY 2023 MOVEit breach, 30,210 Bank of America clients were alerted to the issue. EY's spokesperson assured clients that the current breach did not compromise broader EY enterprise systems and posed no threat to ongoing business. The company has conducted a comprehensive review of the affected data, with the investigation nearing completion. Senior technology executives from the Big Four firms expressed concerns over the complex technology architecture and interconnected global networks, highlighting the communication channel between firms and clients as a potential weak point. Many client communications, especially in India, occur via email services like Gmail, further increasing the risk of sensitive information being exchanged and stored. The Big Four's global networks, characterized by different member firms and geographies, operate on various technology levels, creating gaps in security standards and controls. As firms transition to more integrated technology platforms, the continued presence of legacy systems complicates maintaining uniform security measures across the organization. Experts emphasize the need for a consistent, measurable security baseline across all member firms and external providers while allowing local teams to adapt implementations to regulatory and operational contexts. Indian firms have been advocating for improved cybersecurity standards with the ICAI and other stakeholders, but progress has been limited. This issue is deemed a core national concern by an Indian chartered accountancy firm's CEO.",
  "summary": null,
  "key_points": [
    "EY disclosed data breach exposing client info to Goldman Sachs, Man Group",
    "Unauthorized access via Checkmarx software vulnerability between March 28-April 12, 2026",
    "EY notified regulators in California, Texas, Massachusetts, Vermont"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}