Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
EY

EY Vendor Cyber Rating & Cyber Score

ey.com

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners. Find out more about the EY global network: http://ey.com/en_gl/legal-statement


EY A.I CyberSecurity Scoring

EY
Company Information
Website:http://www.ey.com
Employees number:391,761
Number of followers:10,937,305
NAICS:54
Industry Type:Professional Services
Homepage:ey.com
EY Risk Score (AI oriented)
Between 750 and 799
logo
EYProfessional Services
Updated:
30/03/2026
793/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
EY Global Score (TPRM)
xxxx
logo
EYProfessional Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

EY
EYFair
Current Score
793Baa (FAIR)
01000
5 incidents
-20 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
776Before Incident
MAY 2026
794Before Incident
APRIL 2026
793Before Incident
MARCH 2026
792Before Incident
FEBRUARY 2026
791Before Incident
JANUARY 2026
791Before Incident
DECEMBER 2025
788Before Incident
NOVEMBER 2025
807Before Incident
Breach
05 Nov 2025EY
Ernst & Young (EY)

Ernst & Young (EY) Exposes 4TB Database Backup on Public Internet

787After Incident
HIGH-20
ERN0755607110525
Ernst & Young (EY), a global accounting and consulting firm, inadvertently exposed a 4-terabyte (TB) SQL Server database backup on the public internet. The unsecured .BAK file, discovered by a Neo Security researcher, contained highly sensitive internal data, including database schemas, stored procedures, API keys, session tokens, user credentials, and service account passwords—effectively a 'master blueprint' to EY’s digital infrastructure. While EY confirmed the exposure and claimed no client, personal, or confidential data was compromised, the incident stemmed from an acquired entity under EY Italy, disconnected from its global systems. The file remained accessible for an estimated week before remediation, raising concerns about potential access by malicious actors. EY’s response was praised for professionalism, though the delayed fix highlighted operational vulnerabilities. The exposure risked unauthorized access to critical systems, credential theft, and potential lateral movement within EY’s network, though the firm asserted no evidence of exploitation.
INCIDENT DETAILS -
TYPE
data exposuremisconfiguration
IMPACT
internal database schemastored proceduresAPI keyssession tokensuser credentialsservice account passwordsSQL Server database backup (.BAK file)Brand Reputation Impact: potential reputational harm due to exposure of sensitive internal dataIdentity Theft Risk: high (due to exposed credentials and tokens)
DATA BREACH
internal database schemastored proceduresAPI keyssession tokensuser credentialsservice account passwordsSensitivity Of Data: high (internal credentials, tokens, and technical blueprints)Data Exfiltration: unknown (assumed possible due to public exposure)Data Encryption: no (file was unprotected).BAK (SQL Server backup)Personally Identifiable Information: no (per EY's statement)
OCTOBER 2025
807Before Incident
SEPTEMBER 2025
806Before Incident
AUGUST 2025
805Before Incident
JULY 2025
805Before Incident
MAY 2025
823Before Incident
Breach
01 May 2025EY
EY (Ernst & Young)

EY 4TB+ SQL Server Backup File Exposure

802After Incident
CRITICAL-21
ERN2092220102925
A Dutch cybersecurity firm, Neo Security, discovered a 4TB+ unencrypted SQL Server backup file belonging to EY exposed publicly on the internet due to a misconfigured cloud bucket. The leaked data included API keys, cached authentication tokens, session tokens, service account passwords, and user credentials—essentially a full blueprint for accessing EY’s internal systems. The exposure was caused by a trivial error, likely a misconfigured bucket setting, which made the sensitive backup accessible to anyone. While the exact duration of exposure is unclear, such incidents typically assume compromise from the moment of discovery.The breach mirrors a past case Neo Security investigated, where a lazy database migration (temporarily setting a bucket to public) led to a ransomware attack and the eventual collapse of the affected company after data theft. EY responded professionally upon notification, remediating the issue within a week. However, the exposed credentials and trade secrets pose severe risks, including potential follow-on attacks, financial fraud, or espionage by threat actors who may have already downloaded the data.
INCIDENT DETAILS -
TYPE
data breachcloud misconfigurationunauthorized data exposure
IMPACT
API keyscached authentication tokenssession tokensservice account passwordsuser credentialspotential trade secretsSQL Server backup (BAK file)Brand Reputation Impact: potential reputational damage (high-profile exposure)Identity Theft Risk: high (due to exposed credentials)
DATA BREACH
API keysauthentication tokens (cached)session tokensservice account passwordsuser credentialspotential trade secretsSensitivity Of Data: high (credentials, secrets, and potentially proprietary information)Data Exfiltration: likely (researcher downloaded first 1000 bytes; attackers may have downloaded full file)Data Encryption: no (unencrypted BAK file)SQL Server backup (.BAK)Personally Identifiable Information: potentially (if user credentials included PII)
NOVEMBER 2023
814Before Incident
Breach
01 Nov 2023EY
Infosys

Data Breach at McCamish Systems

780After Incident
CRITICAL-34
INF749032025
India-based IT consulting giant, Infosys, has faced legal challenges due to a data breach in its U.S. subsidiary, McCamish Systems, during November 2023. This breach, which compromised the personal information of approximately 6.5 million individuals, affected customers of Bank of America and Fidelity Investment Life Insurance. A consolidated class action lawsuit was filed, claiming representation of all U.S. residents whose data was exposed. Infosys has agreed to a settle the matter with a $17.5 million payment, which aims to cover remediation efforts and legal claims, appeasing the affected customers and potentially mitigating further financial and reputational damage.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $17.5 millionPersonal InformationClass Action Lawsuit
DATA BREACH
Personal InformationNumber Of Records Exposed: 6.5 million
MAY 2023
832Before Incident
Breach
27 May 2023EY
Ernst & Young LLP

Data Breach at Ernst & Young LLP (EY US)

812After Incident
CRITICAL-20
ERN447072725
On August 9, 2023, the Washington State Office of the Attorney General reported a data breach affecting Ernst & Young LLP (EY US). The breach occurred from May 27, 2023, to May 31, 2023, involving a third-party service vulnerability in Progress Software’s MOVEit Transfer solution. The breach affected 1,129 Washington residents, compromising personal data including names, Social Security numbers, and financial information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High
JUNE 2020
842Before Incident
Breach
16 Jun 2020EY
Ernst & Young (EY)

EY Exposes 4TB SQL Server Backup Publicly on Microsoft Azure

822After Incident
CRITICAL-20
ERN3000430110625
A 4TB SQL Server backup file belonging to Ernst & Young (EY) was discovered publicly exposed on Microsoft Azure by cybersecurity firm Neo Security. The unencrypted .BAK file, identified during routine passive network analysis, likely contained sensitive data such as database schemas, user credentials, API keys, and authentication tokens. Ownership was confirmed via DNS SOA lookup linking to ey.com, though initial searches showed no explicit owner. While EY remediated the exposure swiftly and claimed no client or confidential data was compromised, the incident underscored the high risk of automated scanning tools discovering such leaks. The exposure duration and potential access by malicious actors remained unclear, but past incidents demonstrated that even brief cloud exposures could lead to PII and credential theft. The case highlighted critical gaps in cloud visibility and leak detection, emphasizing the need for continuous attack surface monitoring in complex cloud environments.
INCIDENT DETAILS -
TYPE
data exposuremisconfiguration
IMPACT
potential schemasuser informationAPI keyscredentialsauthentication tokensMicrosoft Azure Blob StorageBrand Reputation Impact: potential reputational risk due to exposure of sensitive backupIdentity Theft Risk: high (if credentials/PII were exposed)
DATA BREACH
SQL Server database backup (.BAK file)potential: schemas, user information, API keys, credentials, authentication tokensSensitivity Of Data: high (potentially included credentials and PII)Data Exfiltration: none confirmed (per EY)Data Encryption: no (file was unencrypted).BAK (SQL Server backup)Personally Identifiable Information: potential (not confirmed)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for EY ?
?
What was EY's A.I Rankiteo Cyber Score in May 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in April 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in March 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in February 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in January 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in December 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in November 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in October 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in September 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in August 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on EY's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with EY ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view EY's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?