Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
EY

EY Vendor Cyber Rating & Cyber Score

ey.com

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners. Find out more about the EY global network: http://ey.com/en_gl/legal-statement


EY A.I CyberSecurity Scoring

EY
Company Information
Website:http://www.ey.com
Employees number:407,870
Number of followers:11,703,543
NAICS:54
Industry Type:Professional Services
Homepage:ey.com
EY Risk Score (AI oriented)
Between 700 and 749
logo
EYProfessional Services
Updated:
29/07/2026
725/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
EY Global Score (TPRM)
xxxx
logo
EYProfessional Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

EY
EYModerate
Current Score
725Ba (MODERATE)
01000
8 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
725Before Incident
JULY 2026
742Before Incident
Breach
30 Jun 2026EY
Ernst & Young and Commonwealth Bank of Australia: Data Breach Scandal: EY Employees Access Top Politician's Banking Details

EY Employees Charged After Allegedly Accessing Australian PM’s Banking Details

723After Incident
CRITICAL-19
ERNCOM1782793723
EY Employees Charged After Allegedly Accessing Australian PM’s Banking Details Two Ernst & Young (EY) employees on temporary assignment at the Commonwealth Bank of Australia (CBA) have been charged with unauthorized access to the personal banking details of Australian Prime Minister Anthony Albanese. The incident, reported by the Australian Financial Review on Tuesday, has raised serious concerns about data privacy and security within financial institutions. The employees, who were also accused of accessing the banking records of at least one EY partner, were dismissed by the firm following the allegations. EY declined to comment on the matter, while a CBA spokesperson stated it would be inappropriate to discuss individual contractor cases. The Australian Federal Police charged two Sydney men in connection with the breach, highlighting vulnerabilities in data protection protocols. The case adds to growing scrutiny of the Big Four accounting firms over their handling of sensitive information. Neither Albanese’s office nor EY has provided further public statements.
INCIDENT DETAILS -
TYPE
Unauthorized Access
IMPACT
Data Compromised: Personal banking detailsSystems Affected: Commonwealth Bank of Australia (CBA) banking systemsBrand Reputation Impact: HighLegal Liabilities: PotentialIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personal banking detailsSensitivity Of Data: HighPersonally Identifiable Information: Yes
JUNE 2026
741Before Incident
MAY 2026
739Before Incident
APRIL 2026
738Before Incident
MARCH 2026
775Before Incident
Breach
28 Mar 2026EY
Ernst & Young: ShinyHunters targets accounting giant EY aka Ernst & Young with Data Breach

ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak

736After Incident
CRITICAL-39
ERN1785357267
ShinyHunters Claims Breach of Ernst & Young, Threatens Data Leak The cybercriminal group ShinyHunters has alleged a breach of Ernst & Young (EY), claiming to have stolen sensitive client data and threatening to publish it on the dark web if demands are not met. On July 29, 2026, the group announced the attack via a Telegram channel, sharing sample screenshots of purportedly stolen data to pressure EY into negotiations. If no agreement is reached, ShinyHunters warned the data would be released starting July 31, 2026. According to EY’s incident response investigation, unauthorized access likely occurred between March 28 and April 12, 2026, during which attackers allegedly exfiltrated tax return files and other confidential client documents. The full extent of the breach remains undisclosed, including the number of affected clients. The incident poses significant risks, as exposed financial and personal data could lead to identity theft, fraud, and targeted phishing attacks. ShinyHunters, known for high-profile extortion campaigns, has previously targeted large organizations across industries, using public leaks and dark web postings to coerce victims. Cybersecurity experts are assessing the authenticity of the leaked samples while investigations continue. No further verified details have been confirmed beyond the attackers’ claims and EY’s preliminary findings.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Tax return files and other confidential client documentsBrand Reputation Impact: SignificantIdentity Theft Risk: High
DATA BREACH
Tax return filesConfidential client documentsSensitivity Of Data: High
Breach
28 Mar 2026EY
Third-party IT service management platform and Ernst & Young: EY says client tax data exposed in third-party IT software breach

EY Data Breach After Third-Party Platform Compromise

736After Incident
CRITICAL-39
CIRERN1784299363
EY Notifies Clients of Data Breach After Third-Party Platform Compromise Ernst & Young (EY) has begun notifying affected individuals following a data breach involving a third-party IT service management platform used by its tax practice. The incident exposed personal and financial information belonging to multiple tax clients, though EY reports no evidence of misuse to date. The breach was detected on April 23, 2026, after EY’s Information Security team identified anomalous activity on the platform. An investigation, supported by an independent cybersecurity firm, determined that unauthorized access occurred between March 28 and April 12, 2026, during which attackers downloaded client-related documents. The affected systems were secured, and federal law enforcement was notified. The compromised platform, used to manage support tickets for tax-related engagements, may have contained sensitive documents, including personal and financial details tied to tax filings. While the exact data exposed varies by individual, EY’s notification letters dated July 13, 2026 confirm that affected parties will receive specific details about their compromised information. As part of its response, EY is offering 24 months of complimentary Experian IdentityWorks credit monitoring and identity restoration services to impacted individuals, with enrollment required by October 31, 2026. The firm has not disclosed the number of affected clients, the identity of the third-party provider, or the threat actor responsible for the breach.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal and financial informationSystems Affected: Third-party IT service management platform (tax practice support tickets)Identity Theft Risk: High
DATA BREACH
Personal informationFinancial informationSensitivity Of Data: HighFile Types Exposed: Tax-related documents
FEBRUARY 2026
791Before Incident
JANUARY 2026
791Before Incident
DECEMBER 2025
788Before Incident
NOVEMBER 2025
807Before Incident
Breach
05 Nov 2025EY
Ernst & Young (EY)

Ernst & Young (EY) Exposes 4TB Database Backup on Public Internet

787After Incident
HIGH-20
ERN0755607110525
Ernst & Young (EY), a global accounting and consulting firm, inadvertently exposed a 4-terabyte (TB) SQL Server database backup on the public internet. The unsecured .BAK file, discovered by a Neo Security researcher, contained highly sensitive internal data, including database schemas, stored procedures, API keys, session tokens, user credentials, and service account passwords—effectively a 'master blueprint' to EY’s digital infrastructure. While EY confirmed the exposure and claimed no client, personal, or confidential data was compromised, the incident stemmed from an acquired entity under EY Italy, disconnected from its global systems. The file remained accessible for an estimated week before remediation, raising concerns about potential access by malicious actors. EY’s response was praised for professionalism, though the delayed fix highlighted operational vulnerabilities. The exposure risked unauthorized access to critical systems, credential theft, and potential lateral movement within EY’s network, though the firm asserted no evidence of exploitation.
INCIDENT DETAILS -
TYPE
data exposuremisconfiguration
IMPACT
internal database schemastored proceduresAPI keyssession tokensuser credentialsservice account passwordsSQL Server database backup (.BAK file)Brand Reputation Impact: potential reputational harm due to exposure of sensitive internal dataIdentity Theft Risk: high (due to exposed credentials and tokens)
DATA BREACH
internal database schemastored proceduresAPI keyssession tokensuser credentialsservice account passwordsSensitivity Of Data: high (internal credentials, tokens, and technical blueprints)Data Exfiltration: unknown (assumed possible due to public exposure)Data Encryption: no (file was unprotected).BAK (SQL Server backup)Personally Identifiable Information: no (per EY's statement)
OCTOBER 2025
807Before Incident
SEPTEMBER 2025
806Before Incident
MAY 2025
823Before Incident
Breach
01 May 2025EY
EY (Ernst & Young)

EY 4TB+ SQL Server Backup File Exposure

802After Incident
CRITICAL-21
ERN2092220102925
A Dutch cybersecurity firm, Neo Security, discovered a 4TB+ unencrypted SQL Server backup file belonging to EY exposed publicly on the internet due to a misconfigured cloud bucket. The leaked data included API keys, cached authentication tokens, session tokens, service account passwords, and user credentials—essentially a full blueprint for accessing EY’s internal systems. The exposure was caused by a trivial error, likely a misconfigured bucket setting, which made the sensitive backup accessible to anyone. While the exact duration of exposure is unclear, such incidents typically assume compromise from the moment of discovery.The breach mirrors a past case Neo Security investigated, where a lazy database migration (temporarily setting a bucket to public) led to a ransomware attack and the eventual collapse of the affected company after data theft. EY responded professionally upon notification, remediating the issue within a week. However, the exposed credentials and trade secrets pose severe risks, including potential follow-on attacks, financial fraud, or espionage by threat actors who may have already downloaded the data.
INCIDENT DETAILS -
TYPE
data breachcloud misconfigurationunauthorized data exposure
IMPACT
API keyscached authentication tokenssession tokensservice account passwordsuser credentialspotential trade secretsSQL Server backup (BAK file)Brand Reputation Impact: potential reputational damage (high-profile exposure)Identity Theft Risk: high (due to exposed credentials)
DATA BREACH
API keysauthentication tokens (cached)session tokensservice account passwordsuser credentialspotential trade secretsSensitivity Of Data: high (credentials, secrets, and potentially proprietary information)Data Exfiltration: likely (researcher downloaded first 1000 bytes; attackers may have downloaded full file)Data Encryption: no (unencrypted BAK file)SQL Server backup (.BAK)Personally Identifiable Information: potentially (if user credentials included PII)
NOVEMBER 2023
814Before Incident
Breach
01 Nov 2023EY
Infosys

Data Breach at McCamish Systems

780After Incident
CRITICAL-34
INF749032025
India-based IT consulting giant, Infosys, has faced legal challenges due to a data breach in its U.S. subsidiary, McCamish Systems, during November 2023. This breach, which compromised the personal information of approximately 6.5 million individuals, affected customers of Bank of America and Fidelity Investment Life Insurance. A consolidated class action lawsuit was filed, claiming representation of all U.S. residents whose data was exposed. Infosys has agreed to a settle the matter with a $17.5 million payment, which aims to cover remediation efforts and legal claims, appeasing the affected customers and potentially mitigating further financial and reputational damage.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $17.5 millionPersonal InformationClass Action Lawsuit
DATA BREACH
Personal InformationNumber Of Records Exposed: 6.5 million
MAY 2023
832Before Incident
Breach
27 May 2023EY
Ernst & Young LLP

Data Breach at Ernst & Young LLP (EY US)

812After Incident
CRITICAL-20
ERN447072725
On August 9, 2023, the Washington State Office of the Attorney General reported a data breach affecting Ernst & Young LLP (EY US). The breach occurred from May 27, 2023, to May 31, 2023, involving a third-party service vulnerability in Progress Software’s MOVEit Transfer solution. The breach affected 1,129 Washington residents, compromising personal data including names, Social Security numbers, and financial information.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High
JUNE 2020
842Before Incident
Breach
16 Jun 2020EY
Ernst & Young (EY)

EY Exposes 4TB SQL Server Backup Publicly on Microsoft Azure

822After Incident
CRITICAL-20
ERN3000430110625
A 4TB SQL Server backup file belonging to Ernst & Young (EY) was discovered publicly exposed on Microsoft Azure by cybersecurity firm Neo Security. The unencrypted .BAK file, identified during routine passive network analysis, likely contained sensitive data such as database schemas, user credentials, API keys, and authentication tokens. Ownership was confirmed via DNS SOA lookup linking to ey.com, though initial searches showed no explicit owner. While EY remediated the exposure swiftly and claimed no client or confidential data was compromised, the incident underscored the high risk of automated scanning tools discovering such leaks. The exposure duration and potential access by malicious actors remained unclear, but past incidents demonstrated that even brief cloud exposures could lead to PII and credential theft. The case highlighted critical gaps in cloud visibility and leak detection, emphasizing the need for continuous attack surface monitoring in complex cloud environments.
INCIDENT DETAILS -
TYPE
data exposuremisconfiguration
IMPACT
potential schemasuser informationAPI keyscredentialsauthentication tokensMicrosoft Azure Blob StorageBrand Reputation Impact: potential reputational risk due to exposure of sensitive backupIdentity Theft Risk: high (if credentials/PII were exposed)
DATA BREACH
SQL Server database backup (.BAK file)potential: schemas, user information, API keys, credentials, authentication tokensSensitivity Of Data: high (potentially included credentials and PII)Data Exfiltration: none confirmed (per EY)Data Encryption: no (file was unencrypted).BAK (SQL Server backup)Personally Identifiable Information: potential (not confirmed)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for EY ?
?
What was EY's A.I Rankiteo Cyber Score in July 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in June 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in May 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in April 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in March 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in February 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in January 2026 ?
?
What was EY's A.I Rankiteo Cyber Score in December 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in November 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in October 2025 ?
?
What was EY's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on EY's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with EY ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view EY's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?