If you received a notice about the July 2026 Ernst & Young data breach, take these six actions now: enroll in the free 24-month Experian monitoring by October 31, 2026, freeze your credit at all three bureaus, request an IRS Identity Protection PIN, place a fraud alert, watch for tax-refund and financial-account phishing, and remove your contact information from data broker sites so attackers can't cross-reference the leaked SSN with your address history. Because tax records and Social Security numbers were exposed, this breach is high-severity — treat it that way.
What Happened in the EY Breach?
Between March 28, 2026 and April 12, 2026, an unauthorized third party accessed a third-party support ticket system used by Ernst & Young's IT personnel and downloaded documents containing client tax information. EY disclosed the breach publicly on July 17, 2026 and filed notifications with the California Attorney General's office on July 15, 2026. The ShinyHunters extortion group later claimed responsibility.
Notices went out to affected individuals throughout late July 2026, offering 24 months of identity monitoring and restoration service through Experian. Enrollment must be completed by October 31, 2026.
What Data Was Exposed?
Per EY's regulatory filings and notification letters, the exposed information may include:
- Full names
- Physical addresses
- Dates of birth
- Social Security numbers
- Driver's license numbers
- Email addresses and phone numbers
- Financial account codes
- Credit and debit account information
- Tax records, including data submitted for EY tax preparation and audit services
Why This Breach Is Worse Than Most
Most consumer breaches leak contact info or partial identifiers. The EY breach exposed the full stack: Social Security number, tax records, financial account codes, and driver's license. That is enough to file a fraudulent tax return in your name, open credit lines, apply for loans, or take over existing accounts. Do not delay the credit freeze and IRS IP PIN steps below.
Step 1: Enroll in the Free 24-Month Experian Monitoring
Read the notification letter you received (or check your email if you were an EY tax client). It includes an activation code for 24 months of Experian IdentityWorks. Enroll before the October 31, 2026 deadline — after that, the offer expires. The service includes credit monitoring across all three bureaus, dark web scans for your SSN, and identity restoration if fraud occurs. It is genuinely useful, but it is reactive, so pair it with the freezes and IP PIN below.
Step 2: Freeze Your Credit at All Three Bureaus
A credit freeze is the single most effective step to prevent identity thieves from opening new accounts in your name using your leaked SSN. It is free, does not affect your credit score, and can be lifted temporarily whenever you legitimately apply for credit.
- Equifax: equifax.com/personal/credit-report-services/credit-freeze
- Experian: experian.com/freeze/center.html
- TransUnion: transunion.com/credit-freeze
Each bureau requires a separate freeze. Save your PINs — you will need them to thaw the freeze later. Also freeze the two lesser bureaus most people forget: Innovis and the National Consumer Telecom & Utilities Exchange (NCTUE), which lenders and cellular providers use.
Step 3: Request an IRS Identity Protection (IP) PIN
Because tax records were exposed, tax-refund fraud is one of the highest risks from this breach. Attackers file a fraudulent return in your name, claim your refund, and cash it before you file. An IRS IP PIN is a six-digit number the IRS requires on your return; without it, any return filed under your SSN is rejected.
- Go to irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin.
- Sign in or create an ID.me account.
- Request your IP PIN. A new one is issued each January.
The IRS also lets you file Form 14039 (Identity Theft Affidavit) if a fraudulent return has already been filed in your name.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Place a Fraud Alert
In addition to a freeze, place a fraud alert with any one of the three bureaus (they will notify the other two). A fraud alert requires creditors to take reasonable steps to verify your identity before opening new accounts. Standard alerts last one year; if you can document identity theft, an extended alert lasts seven years.
Step 5: Watch for Highly Targeted Phishing
With your name, SSN, DOB, address, phone, and financial data all in one package, expect sophisticated attacks designed to bypass your usual skepticism.
- Fake IRS notices claiming you owe back taxes or are due a refund — the IRS never initiates contact by phone, email, or text.
- Fake EY security emails asking you to "verify" your notification or reset a password.
- Bank account takeover attempts — attackers may call your bank pretending to be you, using leaked SSN and DOB to pass verification.
- SIM-swap attacks aimed at capturing 2FA codes sent to your phone number.
- Fake settlement emails from law firms during the class-action period, phishing for further personal data.
Verify Every Contact Independently
Do not trust caller ID, links in emails, or phone numbers in text messages. Look up the official phone number for the IRS (1-800-829-1040), your bank, or EY (EY's dedicated breach line is 833-391-7884, Mon-Fri 8 a.m.-8 p.m. CST) independently, and call that number instead. Attackers spoof caller ID trivially.
Step 6: Remove Your Data From Broker Sites
Here is the step that most breach guides omit but that dramatically reduces long-term risk: the EY-leaked SSN, DOB, and address get cross-referenced against public data broker profiles to build a full identity dossier — including your relatives, past addresses, employers, estimated income, and property records. Attackers use these dossiers to answer knowledge-based identity verification questions ("What was your address in 2015?") that banks and lenders still rely on.
Removing your information from Spokeo, BeenVerified, Whitepages, Intelius, MyLife, TruePeopleSearch, and 100+ other broker sites cuts off the raw material attackers use to weaponize your leaked SSN. This is a one-time and continuous project — brokers re-scrape public records every few weeks — so most people use an automated service to keep listings suppressed.
Should You Join the Class Action?
Multiple plaintiffs' firms filed proposed class-action lawsuits against Ernst & Young within days of the July 17, 2026 disclosure. If you receive a formal notice, read it carefully — you generally have the right to opt out and pursue individual claims or stay in the class and share in any settlement. Breach settlements typically pay $50-$500 per affected consumer without documented harm; documented losses (identity theft, tax fraud, out-of-pocket costs) can qualify for higher amounts.
How PrivacyOn Helps After a Breach Like This
You cannot pull a leaked SSN back — but you can shut down the secondary market that makes it dangerous. PrivacyOn does two things that matter most in the aftermath of a high-severity breach like EY's:
- Removes your data from 100+ broker sites so attackers cannot cross-reference the EY leak with your public profile to answer identity verification questions or build convincing social engineering scripts.
- Monitors the dark web 24/7 for your SSN, email, phone number, and other identifiers, alerting you when your credentials appear in future breaches or combolists — including any future ShinyHunters dumps.
Plans start at $8.33/month, cover up to 5 family members, and include a free scan that shows exactly which broker sites currently list your information — the same profiles attackers pair with leaked SSNs.
Frequently Asked Questions
How do I know if I was affected by the EY breach?
Ernst & Young mailed and emailed notification letters to affected individuals throughout late July 2026. If you were a client of EY's tax preparation, audit, or advisory services between 2020 and 2026, you may be affected even if you have not received a letter yet — check your spam folder and follow up with EY at their dedicated breach line (833-391-7884, Mon-Fri 8 a.m.-8 p.m. CST) or Privacy.Notification@ey.com.
Was my Social Security number exposed in the EY breach?
Per EY's public disclosure and regulatory filings, Social Security numbers were among the data types accessed by the attacker. If your notification letter confirms this, assume your SSN is compromised: freeze your credit at all three bureaus, request an IRS IP PIN, and enroll in the free 24-month Experian monitoring EY is offering.
Is the free Experian monitoring EY is offering enough?
Enroll in it — it is free, useful, and includes 24 months of monitoring plus identity restoration services. But it is not enough on its own. Credit monitoring is reactive: it alerts you after a fraudulent account is opened, not before. A credit freeze prevents new accounts from being opened in the first place, and an IRS IP PIN prevents fraudulent tax returns. Do both alongside the Experian enrollment.
What is ShinyHunters and why did they target EY?
ShinyHunters is a financially motivated extortion group active since 2020, responsible for many of the largest breaches of the decade. In 2026 they have hit Panera Bread, Fluke Corporation, Grubhub, dozens of Salesforce customers, and now EY. They typically compromise third-party support systems, cloud identity providers, or SaaS platforms via social engineering, exfiltrate data, and demand ransom. EY's exposure came through a third-party IT support ticket system, not EY's core network.
Should I file a lawsuit against Ernst & Young?
Multiple class-action lawsuits were filed within days of the July 2026 disclosure. Most affected consumers will be automatically included in the class and receive a settlement notice — no separate filing required. Consult an attorney only if you have concrete losses (identity theft, tax fraud, unauthorized account openings) and want to pursue individual claims outside the class. Class settlements typically pay $50-$500 per consumer absent documented harm.
How do I stop future breaches from exposing my data?
You cannot prevent companies you do business with from being breached, but you can shrink the blast radius. Freeze your credit at all three bureaus and keep it frozen, use an IRS IP PIN every year, use unique passwords managed by a password manager, enable authenticator-app 2FA on every important account, and remove your information from data broker sites so leaked identifiers cannot be cross-referenced into a full identity profile. PrivacyOn automates the broker-removal step across 100+ sites and provides 24/7 dark web monitoring — the single highest-leverage privacy investment you can make in 2026.