Last Update: 08/01/2026 at 2:00 PM EST

Breaches Expose Tax And Personal Data

Coverage from SecurityWeek, TechRadar, and others

Articles

78

Active Days

111

The Topic

Breaches Expose Tax And Personal Data topic image

Organizations including Ernst & Young, US Tiger Securities, and Yellow Corporation disclosed breaches involving the unauthorized access or copying of files containing highly sensitive personal, financial, tax, medical, or employment information. The strongest recurring pattern is exposure through shared, back-office, or third-party systems rather than disruption of customer-facing production services. The incidents matter because tax records, government identifiers, financial data, and health information can enable identity theft, fraud, phishing, and targeted social engineering, while the scope of affected individuals remains unclear in several cases.

First Article: 04/07/26

Latest Article: 07/26/26

History

07/23/20260 new articles

The update adds confirmation that the incidents are being handled with formal regulatory notifications and consumer remediation, while sharpening the operational distinction that US Tiger’s customer-facing trading environment was not breached. It also expands the impact framing by noting the risk of identity theft, fraud, and social engineering from the exposed records.

07/22/20261 new articles

The update adds a more specific, better-substantiated breach example: EY’s third-party platform compromise with a defined intrusion window and potentially downloaded client tax documents. It also sharpens the story with concrete affected-person counts for US Tiger Securities and Yellow Corporation.

  • EY reported a breach of a third-party service management platform.
  • Client documents may have been downloaded between March 28 and April 12, 2026.
  • US Tiger Securities reported at least 26,985 affected people.
  • Yellow reported more than 13,000 affected residents in three states.
  • EY detected the intrusion on April 23, 2026.
07/21/202611 new articles

The story broadened from a general pattern of breach notices to a more specific emphasis on third-party, vendor, and cloud-related exposures, with several new named firms and regulators now recurring in the disclosures. The updated version also adds clearer evidence of delayed discovery and identity/data-specific exposure types such as tax and health records.

07/17/20268 new articles

The story broadened from generic breach notices to a more specific 2026 pattern: repeated disclosures by banks, brokerages, wealth managers, law firms, and employers involving cloud systems, insider misuse, and delayed reporting. That reframes the issue as a concentrated, ongoing access-control problem across sensitive-data holders rather than a set of isolated breaches.

  • TD Bank disclosed an insider access incident.
  • US Tiger Securities reported a virtual-environment breach.
  • Mariner Wealth Advisors was tied to a cloud application compromise.
  • Yellow Corporation disclosed a bankruptcy-era employer data breach.
  • Several notices were filed across Texas, California, Colorado, Kansas, and Tennessee.
06/17/20266 new articles

The story has broadened from a general stream of corporate breach notices into a more explicit pattern of vendor-related incidents, delayed discovery, and multi-state reporting. The new material also adds more recurring state authorities and named firms, reinforcing that this is an ongoing disclosure-and-litigation cycle rather than a one-off set of events.

06/03/20264 new articles

The story broadened from a general breach-notification pattern into a more specific wave of legal and financial-sector incidents, with Mariner Wealth Advisors and Federman & Sherwood newly prominent. The framing also sharpened around cloud, partner, and virtual-environment access questions and potential oversight failures.

05/30/202617 new articles

The story broadened from a general pattern of breach notices into a more specific, denser set of 2025-origin incidents disclosed in 2026, with Maine attorney general filings now standing out as a repeated regulatory thread. The current version also adds new affected organizations and reinforces that third-party access and delayed discovery remain central features.

05/14/2026Topic Formed

Multiple organizations disclosed unauthorized access incidents that exposed sensitive personal data, and law firms continue to investigate whether security controls, vendor oversight, and notification practices were adequate. Most notices were filed through state attorney general channels and paired with credit monitoring offers.